262271
|
- |
|
mcafee
|
smartfilter
|
SmartFilter Web Gateway Security 4.2.1.00 stores user credentials in cleartext in config.txt and uses insecure permissions for this file, which allows local users to gain privileges.
|
CWE-310
Cryptographic Issues
|
CVE-2009-2312
|
2017-08-17 10:30 |
2009-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262272
|
- |
|
horde
|
passwd
|
Cross-site scripting (XSS) vulnerability in passwd/main.php in the Passwd module before 3.1.1 for Horde allows remote attackers to inject arbitrary web script or HTML via the backend parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-2360
|
2017-08-17 10:30 |
2009-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262273
|
- |
|
datachecknh
|
gallerypal_fe
|
SQL injection vulnerability in login.asp in DataCheck Solutions GalleryPal FE 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this info…
|
CWE-89
SQL Injection
|
CVE-2009-2365
|
2017-08-17 10:30 |
2009-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262274
|
- |
|
wxwidgets
|
wxwidgets
|
Integer overflow in the wxImage::Create function in src/common/image.cpp in wxWidgets 2.8.10 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted JP…
|
CWE-189
Numeric Errors
|
CVE-2009-2369
|
2017-08-17 10:30 |
2009-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262275
|
- |
|
tangocms
|
tangocms
|
Cross-site scripting (XSS) vulnerability in the Html::textarea function in application/libraries/Html.php in TangoCMS 2.x before 2.3.0 allows remote attackers to inject arbitrary web script or HTML v…
|
CWE-79
Cross-site Scripting
|
CVE-2009-2376
|
2017-08-17 10:30 |
2009-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262276
|
- |
|
4homepages
|
4images
|
Cross-site scripting (XSS) vulnerability in includes/functions.php in 4images 1.7 through 1.7.7 allows remote attackers to inject arbitrary web script or HTML via vectors related to the url variable.
|
CWE-79
Cross-site Scripting
|
CVE-2009-2380
|
2017-08-17 10:30 |
2009-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262277
|
- |
|
fedorahosted
|
sssd
|
The local_handler_callback function in server/responder/pam/pam_LOCAL_domain.c in sssd 0.4.1 does not properly handle blank-password accounts in the SSSD BE database, which allows context-dependent a…
|
CWE-287
Improper Authentication
|
CVE-2009-2410
|
2017-08-17 10:30 |
2009-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262278
|
- |
|
apple
|
safari
|
Use-after-free vulnerability in the servePendingRequests function in WebCore in WebKit in Apple Safari 4.0 and 4.0.1 allows remote attackers to cause a denial of service (application crash) or possib…
|
CWE-399
Resource Management Errors
|
CVE-2009-2419
|
2017-08-17 10:30 |
2009-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262279
|
- |
|
tor
|
tor
|
Tor before 0.2.0.35 allows remote attackers to cause a denial of service (application crash) via a malformed router descriptor.
|
CWE-20
Improper Input Validation
|
CVE-2009-2425
|
2017-08-17 10:30 |
2009-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262280
|
- |
|
tor
|
tor
|
The connection_edge_process_relay_cell_not_open function in src/or/relay.c in Tor 0.2.x before 0.2.0.35 and 0.1.x before 0.1.2.8-beta allows exit relays to have an unspecified impact by causing contr…
|
NVD-CWE-noinfo
|
CVE-2009-2426
|
2017-08-17 10:30 |
2009-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|