260851
|
- |
|
mozilla
|
firefox
|
Mozilla Firefox 3.5.2 on Windows XP, in some situations possibly involving an incompletely configured protocol handler, does not properly implement setting the document.location property to a value s…
|
NVD-CWE-Other
|
CVE-2009-2975
|
2017-08-17 10:30 |
2009-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260852
|
- |
|
sugarcrm
|
sugarcrm
|
SQL injection vulnerability in SugarCRM 4.5.1o and earlier, 5.0.0k and earlier, and 5.2.0g and earlier, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2009-2978
|
2017-08-17 10:30 |
2009-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260853
|
- |
|
lunascape
|
lunascape
|
Lunascape 5.1.3 and 5.1.4 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a v…
|
NVD-CWE-Other
|
CVE-2009-3005
|
2017-08-17 10:30 |
2009-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260854
|
- |
|
drupal
|
views_bulk_operations
|
Cross-site scripting (XSS) vulnerability in the theme_views_bulk_operations_confirmation function in views_bulk_operations.module in Views Bulk Operations 5.x before 5.x-1.3 and 6.x before 6.x-1.4, a…
|
CWE-79
Cross-site Scripting
|
CVE-2009-0575
|
2017-08-17 10:29 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260855
|
- |
|
sun
|
java_system_directory_server
|
Unspecified vulnerability in Sun Java System Directory Server 5.2 p6 and earlier, and Enterprise Edition 5, allows remote attackers to cause a denial of service (daemon crash) via crafted LDAP reques…
|
NVD-CWE-noinfo
|
CVE-2009-0576
|
2017-08-17 10:29 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260856
|
- |
|
openssl
|
openssl
|
The CMS_verify function in OpenSSL 0.9.8h through 0.9.8j, when CMS is enabled, does not properly handle errors associated with malformed signed attributes, which allows remote attackers to repudiate …
|
CWE-287
Improper Authentication
|
CVE-2009-0591
|
2017-08-17 10:29 |
2009-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260857
|
- |
|
drupal
|
link_module
|
Cross-site scripting (XSS) vulnerability in index.php in the Link module 5.x-2.5 for Drupal 5.10 allows remote authenticated users, with "administer content types" privileges, to inject arbitrary web…
|
CWE-79
Cross-site Scripting
|
CVE-2009-0603
|
2017-08-17 10:29 |
2009-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260858
|
- |
|
cisco
|
session_border_controller
|
Unspecified vulnerability in the Session Border Controller (SBC) before 3.0(2) for Cisco 7600 series routers allows remote attackers to cause a denial of service (SBC card reload) via crafted packets…
|
NVD-CWE-noinfo
|
CVE-2009-0619
|
2017-08-17 10:29 |
2009-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260859
|
- |
|
cisco
|
ios
|
The (1) Cisco Unified Communications Manager Express; (2) SIP Gateway Signaling Support Over Transport Layer Security (TLS) Transport; (3) Secure Signaling and Media Encryption; (4) Blocks Extensible…
|
NVD-CWE-Other
|
CVE-2009-0630
|
2017-08-17 10:29 |
2009-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260860
|
- |
|
cisco
|
unified_communications_manager
|
The IP Phone Personal Address Book (PAB) Synchronizer feature in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.1, 4.2 before 4.2(3)SR4b, 4.3 before 4.3(2)SR1b, 5.x before 5.…
|
CWE-255
Credentials Management
|
CVE-2009-0632
|
2017-08-17 10:29 |
2009-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|