264611
|
- |
|
ibm
|
db2_universal_database
|
Directory traversal vulnerability in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create arbitrary files via a .. (dot dot) in an unspecified environment variable, whi…
|
CWE-22
Path Traversal
|
CVE-2007-4271
|
2011-03-8 11:58 |
2007-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264612
|
- |
|
trend_micro
|
pc-cillin_internet_security_2007 scan_engine
|
The Trend Micro AntiVirus scan engine before 8.550-1001, as used in Trend Micro PC-Cillin Internet Security 2007, and Tmxpflt.sys 8.320.1004 and 8.500.0.1002, has weak permissions (Everyone:Write) fo…
|
CWE-264 CWE-119
Permissions, Privileges, and Access Controls Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-4277
|
2011-03-8 11:58 |
2007-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264613
|
- |
|
knowledgetree
|
open_source
|
Cross-site scripting (XSS) vulnerability in KnowledgeTree Open Source 3.4 and 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the login field on the login page, and other uns…
|
NVD-CWE-Other
|
CVE-2007-4281
|
2011-03-8 11:58 |
2007-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264614
|
- |
|
sun
|
solaris
|
Unspecified vulnerability in the ata disk driver in Sun Solaris 10 on the x86 platform before 20070821 allows local users to cause a denial of service (system panic) via an unspecified ioctl function…
|
NVD-CWE-Other
|
CVE-2007-4495
|
2011-03-8 11:58 |
2007-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264615
|
- |
|
symantec_veritas
|
storage_foundation
|
The Volume Manager Scheduler Service (aka VxSchedService.exe) in Symantec Veritas Storage Foundation 5.0 for Windows allows remote attackers to cause a denial of service (daemon crash or hang) via ma…
|
CWE-20
Improper Input Validation
|
CVE-2007-4516
|
2011-03-8 11:58 |
2008-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264616
|
- |
|
university_of_minnesota
|
mapserver
|
Multiple cross-site scripting (XSS) vulnerabilities in MapServer before 4.10.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the (1) processLine func…
|
CWE-79
Cross-site Scripting
|
CVE-2007-4542
|
2011-03-8 11:58 |
2007-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264617
|
- |
|
realnetworks
|
helix_dna_server
|
Heap-based buffer overflow in the RTSP service in Helix DNA Server before 11.1.4 allows remote attackers to execute arbitrary code via an RSTP command containing multiple Require headers.
|
CWE-119 CWE-20
Incorrect Access of Indexable Resource ('Range Error') Improper Input Validation
|
CVE-2007-4561
|
2011-03-8 11:58 |
2007-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264618
|
- |
|
bharat_mediratta
|
gallery
|
Multiple unspecified vulnerabilities in Gallery before 2.2.3 allow attackers to (1) rename items, (2) read and modify item properties, or (3) lock and replace items via unknown vectors in (a) the Web…
|
NVD-CWE-noinfo CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-4650
|
2011-03-8 11:58 |
2007-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264619
|
- |
|
firebirdsql
|
firebird
|
Unspecified vulnerability in the server in Firebird before 2.0.2 allows remote attackers to determine the existence of arbitrary files, and possibly obtain other "file access," via unknown vectors, a…
|
CWE-264 CWE-119
Permissions, Privileges, and Access Controls Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-4668
|
2011-03-8 11:58 |
2007-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264620
|
- |
|
asterisk
|
asterisk asterisk_appliance_developer_kit asterisknow s800i_appliance
|
The IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before…
|
NVD-CWE-Other
|
CVE-2007-3763
|
2011-03-8 11:57 |
2007-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|