265241
|
- |
|
apple
|
mac_os_x mac_os_x_server
|
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.3 allows user-assisted remote attackers to execute arbitrary code via an (1) Automator, (2) Help, (3) Safari, or (4) Term…
|
NVD-CWE-Other
|
CVE-2008-1032
|
2017-08-8 10:29 |
2008-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265242
|
- |
|
apple
|
mac_os_x mac_os_x_server
|
Per: http://cwe.mitre.org/data/definitions/184.html
'CWE-184: Incomplete Blacklist'
|
NVD-CWE-Other
|
CVE-2008-1032
|
2017-08-8 10:29 |
2008-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265243
|
- |
|
apple
|
cups
|
The scheduler in CUPS in Apple Mac OS X 10.5 before 10.5.3, when debug logging is enabled and a printer requires a password, allows attackers to obtain sensitive information (credentials) by reading …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-1033
|
2017-08-8 10:29 |
2008-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265244
|
- |
|
apple
|
mac_os_x
|
Integer underflow in Help Viewer in Apple Mac OS X before 10.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted help:topic URL that tri…
|
CWE-189
Numeric Errors
|
CVE-2008-1034
|
2017-08-8 10:29 |
2008-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265245
|
- |
|
plume-cms
|
plume_cms
|
Cross-site scripting (XSS) vulnerability in manager/xmedia.php in Plume CMS 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-1048
|
2017-08-8 10:29 |
2008-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265246
|
- |
|
positive_software
|
h-sphere sitestudio
|
Unspecified vulnerability in Parallels SiteStudio before 1.7.2, and 1.8.x before 1.8b, as used in Parallels H-Sphere 3.0 before Patch 9 and 2.5 before Patch 11, has unknown impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2008-1049
|
2017-08-8 10:29 |
2008-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265247
|
- |
|
symark
|
powerbroker
|
Multiple stack-based buffer overflows in Symark PowerBroker 2.8 through 5.0.1 allow local users to gain privileges via a long argv[0] string when executing (1) pbrun, (2) pbsh, or (3) pbksh. NOTE: t…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-1056
|
2017-08-8 10:29 |
2008-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265248
|
- |
|
xoops
|
xm-memberstats
|
Cross-site scripting (XSS) vulnerability index.php in the XM-Memberstats (xmmemberstats) module for XOOPS allows remote attackers to inject arbitrary web script or HTML via the sortby parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-1063
|
2017-08-8 10:29 |
2008-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265249
|
- |
|
xoops
|
xoops_rmsoft_gallery_system
|
Cross-site scripting (XSS) vulnerability in images.php in the Red Mexico RMSOFT Gallery System (GS) 2.0 module (aka rmgs) for XOOPS allows remote attackers to inject arbitrary web script or HTML via …
|
CWE-79
Cross-site Scripting
|
CVE-2008-1064
|
2017-08-8 10:29 |
2008-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265250
|
- |
|
smarty
|
smarty
|
The modifier.regex_replace.php plugin in Smarty before 2.6.19, as used by Serendipity (S9Y) and other products, allows attackers to call arbitrary PHP functions via templates, related to a '\0' chara…
|
CWE-20
Improper Input Validation
|
CVE-2008-1066
|
2017-08-8 10:29 |
2008-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|