260971
|
- |
|
freebsd
|
freebsd
|
The "internal state tracking" code for the random and urandom devices in FreeBSD 5.5, 6.1 through 6.3, and 7.0 beta 4 allows local users to obtain portions of previously-accessed random values, which…
|
CWE-200
Information Exposure
|
CVE-2007-6150
|
2017-07-29 10:34 |
2007-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260972
|
- |
|
gouae
|
dwd_realty
|
SQL injection vulnerability in admin/index2.asp in GOUAE DWD Realty allows remote attackers to execute arbitrary SQL commands via the uname parameter, a different vector than CVE-2007-6163. NOTE: th…
|
CWE-89
SQL Injection
|
CVE-2007-6169
|
2017-07-29 10:34 |
2007-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260973
|
- |
|
phpdevshell
|
phpdevshell
|
PHPDevShell before 0.7.0 allows remote authenticated users to gain privileges via a crafted request to update a user profile. NOTE: some of these details are obtained from third party information.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-6174
|
2017-07-29 10:34 |
2007-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260974
|
- |
|
lhaplus
|
lhaplus
|
Buffer overflow in Lhaplus 1.55 and earlier allows remote attackers to execute arbitrary code via a crafted LZH archive, a different vector than CVE-2007-5048.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-6175
|
2017-07-29 10:34 |
2007-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260975
|
- |
|
sun
|
solaris
|
Race condition in the Remote Procedure Call kernel module (rpcmod) in Sun Solaris 8 through 10 allows local users to cause a denial of service (NULL dereference and panic) via unspecified vectors.
|
CWE-362
Race Condition
|
CVE-2007-6180
|
2017-07-29 10:34 |
2007-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260976
|
- |
|
growth
|
ispmanager
|
The responder program in ISPsystem ISPmanager (aka ISPmgr) 4.2.15.1 allows local users to gain privileges via shell metacharacters in command line arguments.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-6182
|
2017-07-29 10:34 |
2007-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260977
|
- |
|
phpdevshell
|
phpdevshell
|
Unspecified vulnerability in PHPDevShell before 0.7.0 has unknown impact and attack vectors, involving a "minor security bug in repair & optimize database."
|
NVD-CWE-noinfo
|
CVE-2007-6186
|
2017-07-29 10:34 |
2007-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260978
|
- |
|
pmapper
|
p.mapper
|
Multiple PHP remote file inclusion vulnerabilities in Armin Burger p.mapper 3.2.0 beta3 allow remote attackers to execute arbitrary PHP code via a URL in the _SESSION[PM_INCPHP] parameter to (1) incp…
|
CWE-94
Code Injection
|
CVE-2007-6191
|
2017-07-29 10:34 |
2007-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260979
|
- |
|
hp
|
select_identity
|
Unspecified vulnerability in HP Select Identity 4.01 before 4.01.012 and 4.1x before 4.13.003 allows remote attackers to obtain unspecified access via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2007-6194
|
2017-07-29 10:34 |
2007-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260980
|
- |
|
calacode
|
atmail_webmail_system
|
Cross-site scripting (XSS) vulnerability in util.php in Calacode @Mail before 5.2 allows remote attackers to inject arbitrary web script or HTML via the func parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2007-6196
|
2017-07-29 10:34 |
2007-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|