260661
|
- |
|
g4j.laoneo
|
com_gcalendar
|
SQL injection vulnerability in the Google Calendar GCalendar (com_gcalendar) component 1.1.2, 2.1.4, and possibly earlier versions for Joomla! allows remote attackers to execute arbitrary SQL command…
|
CWE-89
SQL Injection
|
CVE-2009-4099
|
2017-08-17 10:31 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260662
|
- |
|
yoono
|
yoono
|
Yoono extension before 6.1.1 for Firefox performs certain operations with chrome privileges, which allows user-assisted remote attackers to execute arbitrary commands and perform cross-domain scripti…
|
CWE-20
Improper Input Validation
|
CVE-2009-4100
|
2017-08-17 10:31 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260663
|
- |
|
yoono
|
yoono
|
Per info from the following advisory:
http://www.net-security.org/secworld.php?id=8527
Raised the score to CIA:complete
NVD received information from Yoono development team on December 4,…
|
CWE-20
Improper Input Validation
|
CVE-2009-4100
|
2017-08-17 10:31 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260664
|
- |
|
yoono
|
yoono
|
NVD received information from Yoono development team on December 4, 2009 that the fixed version is in fact 6.1.1. A patch can be found at the following URL:
https://addons.mozilla.org/en-US/firef…
|
CWE-20
Improper Input Validation
|
CVE-2009-4100
|
2017-08-17 10:31 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260665
|
- |
|
didier_ernotte
|
inforss
|
infoRSS 1.1.4.2 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-domain scripting at…
|
CWE-20
Improper Input Validation
|
CVE-2009-4101
|
2017-08-17 10:31 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260666
|
- |
|
didier_ernotte
|
inforss
|
Per information from the following advisory:
http://www.net-security.org/secworld.php?id=8527
raised the score to CIA:complete since this vulnerability gives attacker the full access to the compute…
|
CWE-20
Improper Input Validation
|
CVE-2009-4101
|
2017-08-17 10:31 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260667
|
- |
|
sage.mozdev mozilla
|
sage firefox
|
Sage 1.4.3 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-domain scripting attacks…
|
CWE-20
Improper Input Validation
|
CVE-2009-4102
|
2017-08-17 10:31 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260668
|
- |
|
sage.mozdev mozilla
|
sage firefox
|
Per info from the following advisory:
http://www.net-security.org/secworld.php?id=8527
Scored this CVE CIA:complete
|
CWE-20
Improper Input Validation
|
CVE-2009-4102
|
2017-08-17 10:31 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260669
|
- |
|
dotnetnuke
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in the search functionality in DotNetNuke 4.8 through 5.1.4 allows remote attackers to inject arbitrary web script or HTML via search terms that are not prope…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4110
|
2017-08-17 10:31 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260670
|
- |
|
alex_barth
|
feed_element_mapper
|
Cross-site scripting (XSS) vulnerability in Feed Element Mapper module 5.x before 5.x-1.3, 6.x before 6.x-1.3, and 6.x-2.0-alpha before 6.x-2.0-alpha4 for Drupal allows remote attackers to inject arb…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4119
|
2017-08-17 10:31 |
2009-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|