266941
|
- |
|
netscape
|
navigator
|
Netscape 4 sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.
|
CWE-200
Information Exposure
|
CVE-2003-1560
|
2009-01-29 14:28 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266942
|
- |
|
opera
|
opera
|
Opera, probably before 7.50, sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer …
|
NVD-CWE-noinfo CWE-200
Information Exposure
|
CVE-2003-1561
|
2009-01-29 14:28 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266943
|
- |
|
webhelpdesk
|
web_help_desk
|
Cross-site scripting (XSS) vulnerability in Web Help Desk before 9.1.18 allows remote attackers to inject arbitrary web script or HTML via vectors related to "encoded JavaScript" and Helpdesk.woa.
|
CWE-79
Cross-site Scripting
|
CVE-2009-0303
|
2009-01-28 14:00 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266944
|
- |
|
ipswitch
|
imail
|
Multiple buffer overflows in Ipswitch IMail before 2006.21 allow remote attackers or authenticated users to execute arbitrary code via (1) the authentication feature in IMailsec.dll, which triggers h…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-2795
|
2009-01-28 14:00 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266945
|
- |
|
ryneezy
|
phosheezy
|
Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into config/header via the header parameter. NOTE: t…
|
CWE-94
Code Injection
|
CVE-2009-0275
|
2009-01-27 05:30 |
2009-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266946
|
- |
|
trilogic
|
media_player
|
Stack-based buffer overflow in Triologic Media Player 8.0.0.0 allows user-assisted remote attackers to execute arbitrary code via a long string in a .m3l playlist file. NOTE: the provenance of this …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-0266
|
2009-01-27 00:30 |
2009-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266947
|
- |
|
bsdi caldera redhat
|
bsd_os openlinux linux
|
Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-1999-0002
|
2009-01-26 14:00 |
1998-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266948
|
- |
|
apple
|
safari
|
An unspecified function in the JavaScript implementation in Apple Safari creates and exposes a "temporary footprint" when there is a current login to a web site, which makes it easier for remote atta…
|
NVD-CWE-Other
|
CVE-2008-5914
|
2009-01-24 00:44 |
2009-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266949
|
- |
|
asp-dev
|
xm_events_diary
|
SQL injection vulnerability in default.asp in ASP-DEv XM Events Diary allows remote attackers to execute arbitrary SQL commands the cat parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5923
|
2009-01-24 00:08 |
2009-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266950
|
- |
|
asp-dev
|
xm_events_diary
|
ASP-DEv XM Events Diary stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for diary.md…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5925
|
2009-01-23 23:58 |
2009-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|