257211
|
- |
|
thekelleys
|
dnsmasq
|
Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, might allow remote attackers to execute arbitrary code via a long filename in a T…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-2957
|
2017-09-19 10:29 |
2009-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257212
|
- |
|
thekelleys
|
dnsmasq
|
The tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TFTP rea…
|
CWE-399
Resource Management Errors
|
CVE-2009-2958
|
2017-09-19 10:29 |
2009-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257213
|
- |
|
kolmck
|
kol_player
|
Stack-based buffer overflow in Thaddy de Konng KOL Player 1.0 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL in a .MP3 playlist file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-2961
|
2017-09-19 10:29 |
2009-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257214
|
- |
|
squirrelmail
|
squirrelmail
|
Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.19 and earlier, and NaSMail before 1.7, allow remote attackers to hijack the authentication of unspecified victims via f…
|
CWE-352
Origin Validation Error
|
CVE-2009-2964
|
2017-09-19 10:29 |
2009-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257215
|
- |
|
sun
|
solaris
|
in.lpd in the print service in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors that trigger a "fork()/exec() bomb."
|
CWE-399
Resource Management Errors
|
CVE-2009-2972
|
2017-09-19 10:29 |
2009-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257216
|
- |
|
microsoft
|
internet_explorer
|
Microsoft Internet Explorer 6 through 8 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demon…
|
NVD-CWE-Other
|
CVE-2009-3003
|
2017-09-19 10:29 |
2009-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257217
|
- |
|
maxthon
|
maxthon_browser
|
Maxthon Browser 2.5.3.80 UNICODE allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated…
|
NVD-CWE-Other
|
CVE-2009-3006
|
2017-09-19 10:29 |
2009-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257218
|
- |
|
apple
|
safari
|
Apple Safari 4.0.3 does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors rel…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3016
|
2017-09-19 10:29 |
2009-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257219
|
- |
|
microsoft
|
internet_explorer
|
Microsoft Internet Explorer 6 on Windows XP SP2 and SP3, and Internet Explorer 7 on Vista, allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls crea…
|
CWE-94
Code Injection
|
CVE-2009-3019
|
2017-09-19 10:29 |
2009-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257220
|
- |
|
pidgin
|
pidgin
|
Unspecified vulnerability in Pidgin 2.6.0 allows remote attackers to cause a denial of service (crash) via a link in a Yahoo IM.
|
NVD-CWE-noinfo
|
CVE-2009-3025
|
2017-09-19 10:29 |
2009-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|