266651
|
- |
|
novell
|
identity_manager
|
The engine installer in Novell Identity Manager (aka IDM) 3.6.1 stores admin tree credentials in /tmp/idmInstall.log, which allows local users to obtain sensitive information by reading this file.
|
CWE-255
Credentials Management
|
CVE-2010-3264
|
2010-09-9 13:00 |
2010-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266652
|
- |
|
blackboard
|
transact_suite
|
BbtsConnection_Edit.exe in Blackboard Transact Suite (formerly Blackboard Commerce Suite) before 3.6.0.2 relies on field names when determining whether it is appropriate to decrypt a connection.xml f…
|
CWE-200
Information Exposure
|
CVE-2010-3244
|
2010-09-9 02:43 |
2010-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266653
|
- |
|
gnome
|
power_manager
|
gnome-power-manager 2.27.92 does not properly implement the lock_on_suspend and lock_on_hibernate settings for locking the screen when the suspend or hibernate button is pressed, which might make it …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-4997
|
2010-09-9 02:08 |
2010-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266654
|
- |
|
gnome
|
power_manager
|
gnome-power-manager 2.14.0 does not properly implement the lock_on_suspend and lock_on_hibernate settings for locking the screen when the suspend or hibernate button is pressed, which might make it e…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-7240
|
2010-09-9 00:26 |
2010-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266655
|
- |
|
mozilla
|
bugzilla
|
Search.pm in Bugzilla 2.19.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 allows remote attackers to determine the group memberships of arbitrary users via vectors i…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-2756
|
2010-09-8 14:48 |
2010-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266656
|
- |
|
mozilla
|
bugzilla
|
The sudo feature in Bugzilla 2.22rc1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 does not properly send impersonation notifications, which makes it easier for remot…
|
CWE-310
Cryptographic Issues
|
CVE-2010-2757
|
2010-09-8 14:48 |
2010-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266657
|
- |
|
mozilla
|
bugzilla
|
Bugzilla 2.17.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 generates different error messages depending on whether a product exists, which makes it easier for remo…
|
CWE-200
Information Exposure
|
CVE-2010-2758
|
2010-09-8 14:48 |
2010-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266658
|
- |
|
mozilla
|
bugzilla
|
Bugzilla 2.23.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2, when PostgreSQL is used, does not properly handle large integers in (1) bug and (2) attachment phrases,…
|
CWE-189
Numeric Errors
|
CVE-2010-2759
|
2010-09-8 14:48 |
2010-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266659
|
- |
|
redhat
|
spice-xpi
|
The SPICE (aka spice-xpi) plug-in 2.2 for Firefox allows local users to overwrite arbitrary files via a symlink attack on an unspecified log file.
|
CWE-59
Link Following
|
CVE-2010-2794
|
2010-09-8 14:48 |
2010-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266660
|
- |
|
novell
|
suse_linux
|
WebYaST in yast2-webclient in SUSE Linux Enterprise (SLE) 11 on the WebYaST appliance uses a fixed secret key that is embedded in the appliance's image, which allows remote attackers to spoof session…
|
CWE-255
Credentials Management
|
CVE-2010-1507
|
2010-09-6 13:00 |
2010-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|