262261
|
- |
|
freebsd
|
freebsd
|
FreeBSD 6.3, 6.4, 7.1, and 7.2 does not enforce permissions on the SIOCSIFINFO_IN6 IOCTL, which allows local users to modify or disable IPv6 network interfaces, as demonstrated by modifying the MTU.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-2208
|
2017-08-17 10:30 |
2009-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262262
|
- |
|
citrix
|
secure_gateway
|
The Secure Gateway service in Citrix Secure Gateway 3.1 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an unspecified request.
|
CWE-399
Resource Management Errors
|
CVE-2009-2214
|
2017-08-17 10:30 |
2009-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262263
|
- |
|
jbmc-software
|
directadmin
|
Cross-site scripting (XSS) vulnerability in CMD_REDIRECT in DirectAdmin 1.33.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the URI in a view=advanced request.
|
CWE-79
Cross-site Scripting
|
CVE-2009-2216
|
2017-08-17 10:30 |
2009-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262264
|
- |
|
phantom-inker
|
nbbc
|
Cross-site scripting (XSS) vulnerability in NBBC before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via an invalid URL in a BBCode img tag.
|
CWE-79
Cross-site Scripting
|
CVE-2009-2217
|
2017-08-17 10:30 |
2009-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262265
|
- |
|
surething
|
surething_cd\/dvd_labeler
|
Stack-based buffer overflow in SureThing CD/DVD Labeler 5.1.616 trial version allows user-assisted remote attackers to execute arbitrary code via a crafted (1) m3u or (2) pls playlist file. NOTE: th…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-2225
|
2017-08-17 10:30 |
2009-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262266
|
- |
|
softbizscripts
|
banner_ad_management_script
|
SQL injection vulnerability in image.php in Softbiz Banner Ad Management Script allows remote attackers to execute arbitrary SQL commands via the size_id parameter. NOTE: the provenance of this info…
|
CWE-89
SQL Injection
|
CVE-2009-2232
|
2017-08-17 10:30 |
2009-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262267
|
- |
|
karim_ratib
|
views_bulk_operations
|
Unspecified vulnerability in Views Bulk Operations 5.x-1.x before 5.x-1.4 and 6.x-1.x before 6.x-1.7, a module for Drupal, allows remote attackers to bypass intended access restrictions and modify "n…
|
NVD-CWE-noinfo
|
CVE-2009-2237
|
2017-08-17 10:30 |
2009-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262268
|
- |
|
aaronoutpost
|
asp_inline_corporate_calendar
|
SQL injection vulnerability in active_appointments.asp in ASP Inline Corporate Calendar allows remote attackers to execute arbitrary SQL commands via the sortby parameter. NOTE: the provenance of th…
|
CWE-89
SQL Injection
|
CVE-2009-2243
|
2017-08-17 10:30 |
2009-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262269
|
- |
|
appleple
|
a-news
|
Cross-site scripting (XSS) vulnerability in Appleple a-News 2.32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2009-2292
|
2017-08-17 10:30 |
2009-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262270
|
- |
|
sun
|
opensolaris solaris
|
The NFSv4 server kernel module in Sun Solaris 10, and OpenSolaris before snv_119, does not properly implement the nfs_portmon setting, which allows remote attackers to access shares, and read, create…
|
NVD-CWE-Other
|
CVE-2009-2296
|
2017-08-17 10:30 |
2009-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|