260501
|
- |
|
kaspersky
|
kaspersky_anti-virus kaspersky_internet_security
|
avp.exe in Kaspersky Internet Security 9.0.0.459 and Anti-Virus 9.0.0.463 allows remote attackers to cause a denial of service (CPU consumption and network connectivity loss) via an HTTP URL request …
|
CWE-399
Resource Management Errors
|
CVE-2009-2966
|
2017-08-17 10:30 |
2009-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260502
|
- |
|
buildbot
|
buildbot
|
Multiple cross-site scripting (XSS) vulnerabilities in Buildbot 0.7.6 through 0.7.11p2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, different vulnerabilities…
|
CWE-79
Cross-site Scripting
|
CVE-2009-2967
|
2017-08-17 10:30 |
2009-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260503
|
- |
|
google
|
chrome
|
Google Chrome before 2.0.172.43 does not prevent SSL connections to a site with an X.509 certificate signed with the (1) MD2 or (2) MD4 algorithm, which makes it easier for man-in-the-middle attacker…
|
CWE-310
Cryptographic Issues
|
CVE-2009-2973
|
2017-08-17 10:30 |
2009-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260504
|
- |
|
mozilla
|
firefox
|
Mozilla Firefox 3.5.2 on Windows XP, in some situations possibly involving an incompletely configured protocol handler, does not properly implement setting the document.location property to a value s…
|
NVD-CWE-Other
|
CVE-2009-2975
|
2017-08-17 10:30 |
2009-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260505
|
- |
|
sugarcrm
|
sugarcrm
|
SQL injection vulnerability in SugarCRM 4.5.1o and earlier, 5.0.0k and earlier, and 5.2.0g and earlier, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2009-2978
|
2017-08-17 10:30 |
2009-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260506
|
- |
|
lunascape
|
lunascape
|
Lunascape 5.1.3 and 5.1.4 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a v…
|
NVD-CWE-Other
|
CVE-2009-3005
|
2017-08-17 10:30 |
2009-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260507
|
- |
|
drupal
|
views_bulk_operations
|
Cross-site scripting (XSS) vulnerability in the theme_views_bulk_operations_confirmation function in views_bulk_operations.module in Views Bulk Operations 5.x before 5.x-1.3 and 6.x before 6.x-1.4, a…
|
CWE-79
Cross-site Scripting
|
CVE-2009-0575
|
2017-08-17 10:29 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260508
|
- |
|
sun
|
java_system_directory_server
|
Unspecified vulnerability in Sun Java System Directory Server 5.2 p6 and earlier, and Enterprise Edition 5, allows remote attackers to cause a denial of service (daemon crash) via crafted LDAP reques…
|
NVD-CWE-noinfo
|
CVE-2009-0576
|
2017-08-17 10:29 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260509
|
- |
|
openssl
|
openssl
|
The CMS_verify function in OpenSSL 0.9.8h through 0.9.8j, when CMS is enabled, does not properly handle errors associated with malformed signed attributes, which allows remote attackers to repudiate …
|
CWE-287
Improper Authentication
|
CVE-2009-0591
|
2017-08-17 10:29 |
2009-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260510
|
- |
|
drupal
|
link_module
|
Cross-site scripting (XSS) vulnerability in index.php in the Link module 5.x-2.5 for Drupal 5.10 allows remote authenticated users, with "administer content types" privileges, to inject arbitrary web…
|
CWE-79
Cross-site Scripting
|
CVE-2009-0603
|
2017-08-17 10:29 |
2009-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|