257321
|
- |
|
mozilla
|
firefox
|
The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbit…
|
CWE-399
Resource Management Errors
|
CVE-2009-1169
|
2017-09-29 10:34 |
2009-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257322
|
- |
|
mozilla
|
firefox
|
Per: http://www.securityfocus.com/bid/34235/info
Mozilla Firefox is prone to a remote memory-corruption vulnerability.
An attacker can exploit this issue to execute arbitrary code within the co…
|
CWE-399
Resource Management Errors
|
CVE-2009-1169
|
2017-09-29 10:34 |
2009-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257323
|
- |
|
apple
|
cups
|
The directory-services functionality in the scheduler in CUPS 1.1.17 and 1.1.22 allows remote attackers to cause a denial of service (cupsd daemon outage or crash) via manipulations of the timing of …
|
CWE-399
Resource Management Errors
|
CVE-2009-1196
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257324
|
- |
|
sun
|
opensolaris solaris
|
Race condition in the dircmp script in Sun Solaris 8 through 10, and OpenSolaris snv_01 through snv_111, allows local users to overwrite arbitrary files, probably involving a symlink attack on tempor…
|
CWE-362
Race Condition
|
CVE-2009-1207
|
2017-09-29 10:34 |
2009-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257325
|
- |
|
w3
|
amaya
|
Stack-based buffer overflow in W3C Amaya Web Browser 11.1 allows remote attackers to execute arbitrary code via a script tag with a long defer attribute.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-1209
|
2017-09-29 10:34 |
2009-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257326
|
- |
|
scivox
|
vsp_stats_processor
|
SQL injection vulnerability in vsp-core/pub/themes/bismarck/gamestat.php in vsp stats processor 0.45 allows remote attackers to execute arbitrary SQL commands via the gameID parameter.
|
CWE-89
SQL Injection
|
CVE-2009-1224
|
2017-09-29 10:34 |
2009-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257327
|
- |
|
podcast_generator
|
podcast_generator
|
core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions, which allows remote attackers to delete arbitrary files via the file paramete…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-1226
|
2017-09-29 10:34 |
2009-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257328
|
- |
|
arcadwy
|
arcadwy_arcade_script_cms
|
Cross-site scripting (XSS) vulnerability in register.php in Arcadwy Arcade Script CMS allows remote attackers to inject arbitrary web script or HTML via the username field (user_name parameter).
|
CWE-79
Cross-site Scripting
|
CVE-2009-1228
|
2017-09-29 10:34 |
2009-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257329
|
- |
|
arcadwy
|
arcadwy_arcade_script
|
SQL injection vulnerability in Arcadwy Arcade Script allows remote attackers to execute arbitrary SQL commands via the user cookie parameter.
|
CWE-89
SQL Injection
|
CVE-2009-1229
|
2017-09-29 10:34 |
2009-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257330
|
- |
|
podcast_generator
|
podcast_generator
|
Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated administrators to inject arbitrary PHP code into config.php via the recent parameter …
|
CWE-94
Code Injection
|
CVE-2009-1230
|
2017-09-29 10:34 |
2009-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|