262761
|
- |
|
apple
|
safari
|
Cross-site scripting (XSS) vulnerability in Web Inspector in WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to inject arbitrary web script or HTML, and read local files, via …
|
CWE-79
Cross-site Scripting
|
CVE-2009-1714
|
2017-08-17 10:30 |
2009-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262762
|
- |
|
apple
|
mac_os_x mac_os_x_server
|
CFNetwork in Apple Mac OS X 10.5 before 10.5.8 places an incorrect URL in a certificate warning in certain 302 redirection scenarios, which makes it easier for remote attackers to trick a user into v…
|
NVD-CWE-Other
|
CVE-2009-1723
|
2017-08-17 10:30 |
2009-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262763
|
- |
|
apple
|
mac_os_x mac_os_x_server
|
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X 10.5 before 10.5.8 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a do…
|
NVD-CWE-Other
|
CVE-2009-1727
|
2017-08-17 10:30 |
2009-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262764
|
- |
|
apple
|
mac_os_x mac_os_x_server
|
Stack-based buffer overflow in Image RAW in Apple Mac OS X 10.5 before 10.5.8, and 10.4 before Digital Camera RAW Compatibility Update 2.6, allows remote attackers to execute arbitrary code or cause …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-1728
|
2017-08-17 10:30 |
2009-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262765
|
- |
|
mlffat
|
mlffat
|
SQL injection vulnerability in panel/index.php in MLFFAT 2.1 allows remote attackers to execute arbitrary SQL commands via a base64-encoded supervisor cookie.
|
CWE-89
SQL Injection
|
CVE-2009-1731
|
2017-08-17 10:30 |
2009-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262766
|
- |
|
richard_ellerbrock
|
ipplan
|
Cross-site request forgery (CSRF) vulnerability in IPplan 4.91a allows remote attackers to hijack the authentication of administrators for requests that (1) change the password, (2) add users, or (3)…
|
CWE-352
Origin Validation Error
|
CVE-2009-1733
|
2017-08-17 10:30 |
2009-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262767
|
- |
|
diqiye
|
mypic
|
Directory traversal vulnerability in bom.php in MyPic 2.1 allows remote attackers to list files in arbitrary directories via a .. (dot dot) in the dir parameter.
|
CWE-22
Path Traversal
|
CVE-2009-1737
|
2017-08-17 10:30 |
2009-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262768
|
- |
|
ivanjaros
|
feed_block
|
Cross-site scripting (XSS) vulnerability in Feed Block 6.x-1.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with administrator feed permissions to inject arbitrary web scrip…
|
CWE-79
Cross-site Scripting
|
CVE-2009-1738
|
2017-08-17 10:30 |
2009-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262769
|
- |
|
dlink
|
mpeg4_viewer_activex_control
|
Multiple heap-based buffer overflows in the D-Link MPEG4 Viewer ActiveX Control (csviewer.ocx) 2.11.918.2006 allow remote attackers to execute arbitrary code via a long argument to the (1) SetFilePat…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-1740
|
2017-08-17 10:30 |
2009-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262770
|
- |
|
simone_rota
|
slim_simple_login_manager
|
SLiM Simple Login Manager 1.3.0 places the X authority magic cookie (mcookie) on the command line when invoking xauth from (1) app.cpp and (2) switchuser.cpp, which allows local users to access the X…
|
CWE-200
Information Exposure
|
CVE-2009-1756
|
2017-08-17 10:30 |
2009-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|