264241
|
- |
|
hp
|
palm_webos
|
HP Palm webOS 1.4.5 and 1.4.5.1 does not properly restrict Plug-in Development Kit (PDK) applications, which allows local users to gain privileges by leveraging unintended filesystem write access.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-1738
|
2011-09-7 12:16 |
2011-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264242
|
- |
|
maynard_johnson
|
oprofile
|
utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to conduct eval injection attacks and gain privileges via shell metacharacters in the -e argument.
|
CWE-94
Code Injection
|
CVE-2011-1760
|
2011-09-7 12:16 |
2011-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264243
|
- |
|
banu
|
tinyproxy
|
Integer overflow in conf.c in Tinyproxy before 1.8.3 might allow remote attackers to bypass intended access restrictions in opportunistic circumstances via a TCP connection, related to improper handl…
|
CWE-189
Numeric Errors
|
CVE-2011-1843
|
2011-09-7 12:16 |
2011-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264244
|
- |
|
hp
|
business_availability_center
|
Cross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 8.06 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2011-1856
|
2011-09-7 12:16 |
2011-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264245
|
- |
|
cisco
|
anyconnect_secure_mobility_client
|
The Start Before Logon (SBL) functionality in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.254 on Windows, and on Windows Mobile, allows local users to gain pri…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-2041
|
2011-09-7 12:16 |
2011-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264246
|
- |
|
adobe
|
blazeds livecycle_data_services livecycle
|
Adobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier do not properly restrict creation of classes during deserialization of (1) AMF and (2) AMFX…
|
CWE-20
Improper Input Validation
|
CVE-2011-2092
|
2011-09-7 12:16 |
2011-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264247
|
- |
|
balbir_singh
|
libcgroup
|
The cgre_receive_netlink_msg function in daemon/cgrulesengd.c in cgrulesengd in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 does not verify that netlink messages or…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-1022
|
2011-09-7 12:15 |
2011-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264248
|
- |
|
proftpd
|
proftpd
|
Integer overflow in the mod_sftp (aka SFTP) module in ProFTPD 1.3.3d and earlier allows remote attackers to cause a denial of service (memory consumption leading to OOM kill) via a malformed SSH mess…
|
CWE-189
Numeric Errors
|
CVE-2011-1137
|
2011-09-7 12:15 |
2011-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264249
|
- |
|
exim
|
exim
|
The DKIM implementation in Exim 4.7x before 4.76 permits matching for DKIM identities to apply to lookup items, instead of only strings, which allows remote attackers to execute arbitrary code or acc…
|
CWE-20
Improper Input Validation
|
CVE-2011-1407
|
2011-09-7 12:15 |
2011-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264250
|
- |
|
mediawiki
|
mediawiki
|
api.php in MediaWiki before 1.15.5 does not prevent use of public caching headers for private data, which allows remote attackers to bypass intended access restrictions and obtain sensitive informati…
|
CWE-200
Information Exposure
|
CVE-2010-2787
|
2011-09-7 12:10 |
2011-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|