268521
|
- |
|
-
|
-
|
property.php in Widget Property 1.1.19 allows remote attackers to obtain the full server path via an invalid lang value, which leaks the path in the resulting error message.
|
NVD-CWE-Other
|
CVE-2005-4017
|
2008-09-20 13:41 |
2005-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268522
|
- |
|
simplemedia
|
simplebbs
|
SQL injection vulnerability in SimpleBBS 1.1 allows remote attackers to execute arbitrary SQL commands via unspecified search module parameters.
|
CWE-89
SQL Injection
|
CVE-2005-4027
|
2008-09-20 13:41 |
2005-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268523
|
- |
|
debian
|
python-dns
|
PyDNS (aka python-dns) before 2.3.1-4 in Debian GNU/Linux does not use random source ports or transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a di…
|
CWE-16
Configuration
|
CVE-2008-4099
|
2008-09-19 13:00 |
2008-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268524
|
- |
|
debian
|
python-dns
|
PyDNS (aka python-dns) before 2.3.1-5 in Debian GNU/Linux does not use random source ports for DNS requests and does not use random transaction IDs for DNS retries, which makes it easier for remote a…
|
CWE-16
Configuration
|
CVE-2008-4126
|
2008-09-19 13:00 |
2008-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268525
|
- |
|
lxde
|
lightweight_x11_desktop_environment
|
src/main-win.c in GPicView 0.1.9 in Lightweight X11 Desktop Environment (LXDE) allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rot.jpg temporary file.
|
CWE-59
Link Following
|
CVE-2008-3791
|
2008-09-17 14:35 |
2008-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268526
|
- |
|
apple
|
iphone
|
Apple iPhone 2.0.2, in some configurations, allows physically proximate attackers to bypass intended access restrictions, and obtain sensitive information or make arbitrary use of the device, via an …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-3876
|
2008-09-17 14:35 |
2008-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268527
|
- |
|
six_apart
|
movable_type
|
Cross-site scripting (XSS) vulnerability in Movable Type (MT) 4.x through 4.20, and 3.36 and earlier; Movable Type Enterprise 4.x through 4.20, and 1.54 and earlier; and Movable Type Community Soluti…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4079
|
2008-09-16 00:14 |
2008-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268528
|
- |
|
texmedia
|
million_pixel_script
|
SQL injection vulnerability in tops_top.php in Million Pixel Ad Script (Million Pixel Script) allows remote attackers to execute arbitrary SQL commands via the id_cat parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4055
|
2008-09-12 13:00 |
2008-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268529
|
- |
|
apple
|
itunes
|
Apple iTunes before 8.0 on Mac OS X 10.4.11, when iTunes Music Sharing is enabled but blocked by the host-based firewall, presents misleading information about firewall security, which might allow re…
|
CWE-200
Information Exposure
|
CVE-2008-3634
|
2008-09-11 13:00 |
2008-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268530
|
- |
|
opensuse
|
opensuse
|
Multiple off-by-one errors in opensuse-updater in openSUSE 10.2 have unspecified impact and attack vectors. NOTE: the vendor states that these "can be considered no security problem."
|
NVD-CWE-noinfo CWE-189
Numeric Errors
|
CVE-2008-2388
|
2008-09-11 10:10 |
2008-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|