260231
|
- |
|
ronan_dowling
|
nodehierarchy
|
Cross-site scripting (XSS) vulnerability in the Node Hierarchy module 5.x before 5.x-1.3 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML vi…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3916
|
2017-08-17 10:31 |
2009-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260232
|
- |
|
greg_knaddison
|
s5
|
Cross-site scripting (XSS) vulnerability in the S5 Presentation Player module 6.x-1.x before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via an unspecified field…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3917
|
2017-08-17 10:31 |
2009-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260233
|
- |
|
karim_ratib
|
zoomify
|
Cross-site scripting (XSS) vulnerability in the Zoomify module 5.x before 5.x-2.2 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the n…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3918
|
2017-08-17 10:31 |
2009-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260234
|
- |
|
sean_robertson
|
crmngp
|
Cross-site scripting (XSS) vulnerability in the NGP COO/CWP Integration (crmngp) module 6.x before 6.x-1.12 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified "…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3919
|
2017-08-17 10:31 |
2009-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260235
|
- |
|
sean_robertson
|
crmngp
|
An administration page in the NGP COO/CWP Integration (crmngp) module 6.x before 6.x-1.12 for Drupal does not perform the expected access control, which allows remote attackers to read log informatio…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-3920
|
2017-08-17 10:31 |
2009-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260236
|
- |
|
chad_phillips
|
userprotect
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the User Protect module 5.x before 5.x-1.4 and 6.x before 6.x-1.3, a module for Drupal, allow remote attackers to hijack the authenticati…
|
CWE-352
Origin Validation Error
|
CVE-2009-3922
|
2017-08-17 10:31 |
2009-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260237
|
- |
|
sun
|
virtual_desktop_infrastructure virtualbox
|
The VirtualBox 2.0.8 and 2.0.10 web service in Sun Virtual Desktop Infrastructure (VDI) 3.0 does not require authentication, which allows remote attackers to obtain unspecified access via vectors inv…
|
CWE-287
Improper Authentication
|
CVE-2009-3923
|
2017-08-17 10:31 |
2009-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260238
|
- |
|
raven_software punkbuster
|
soldier_of_fortune_2 punkbuster
|
Buffer overflow in pbsv.dll, as used in Soldier of Fortune II and possibly other applications when Even Balance PunkBuster 1.728 or earlier is enabled, allows remote attackers to cause a denial of se…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-3924
|
2017-08-17 10:31 |
2009-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260239
|
- |
|
google
|
chrome
|
Incomplete blacklist vulnerability in browser/download/download_exe.cc in Google Chrome before 3.0.195.32 allows remote attackers to force the download of certain dangerous files via a "Content-Dispo…
|
CWE-20
Improper Input Validation
|
CVE-2009-3931
|
2017-08-17 10:31 |
2009-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260240
|
- |
|
webkit
|
webkit
|
WebKit before r50173, as used in Google Chrome before 3.0.195.32, allows remote attackers to cause a denial of service (CPU consumption) via a web page that calls the JavaScript setInterval method, w…
|
CWE-399
Resource Management Errors
|
CVE-2009-3933
|
2017-08-17 10:31 |
2009-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|