260401
|
- |
|
apple
|
safari
|
Use-after-free vulnerability in the servePendingRequests function in WebCore in WebKit in Apple Safari 4.0 and 4.0.1 allows remote attackers to cause a denial of service (application crash) or possib…
|
CWE-399
Resource Management Errors
|
CVE-2009-2419
|
2017-08-17 10:30 |
2009-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260402
|
- |
|
tor
|
tor
|
Tor before 0.2.0.35 allows remote attackers to cause a denial of service (application crash) via a malformed router descriptor.
|
CWE-20
Improper Input Validation
|
CVE-2009-2425
|
2017-08-17 10:30 |
2009-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260403
|
- |
|
tor
|
tor
|
The connection_edge_process_relay_cell_not_open function in src/or/relay.c in Tor 0.2.x before 0.2.0.35 and 0.1.x before 0.1.2.8-beta allows exit relays to have an unspecified impact by causing contr…
|
NVD-CWE-noinfo
|
CVE-2009-2426
|
2017-08-17 10:30 |
2009-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260404
|
- |
|
mcafee
|
smartfilter
|
SmartFilter Web Gateway Security 4.2.1.00 stores user credentials in cleartext in admin_backup.xml files and uses insecure permissions for these files, which allows local users to gain privileges. N…
|
CWE-255
Credentials Management
|
CVE-2009-2429
|
2017-08-17 10:30 |
2009-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260405
|
- |
|
ibm
|
aix
|
Buffer overflow in the syscall implementation in IBM AIX 5.3 allows local users to gain privileges via unspecified vectors.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-2434
|
2017-08-17 10:30 |
2009-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260406
|
- |
|
esoftpro
|
online_guestbook_pro
|
Cross-site scripting (XSS) vulnerability in ogp_show.php in Online Guestbook Pro 5.1 allows remote attackers to inject arbitrary web script or HTML via the entry parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-2441
|
2017-08-17 10:30 |
2009-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260407
|
- |
|
siteframe
|
siteframe_cms
|
Siteframe 3.2.3, and other 3.2.x versions, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-2443
|
2017-08-17 10:30 |
2009-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260408
|
- |
|
adbnewssender
|
adbnewssender
|
Directory traversal vulnerability in maillinglist/setup/step1.php.inc in ADbNewsSender before 1.5.6, and 2.0 before RC2, allows remote attackers to include and execute arbitrary local files via a .. …
|
CWE-22
Path Traversal
|
CVE-2009-2444
|
2017-08-17 10:30 |
2009-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260409
|
- |
|
novell
|
edirectory
|
The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial of service (ndsd core dump) via an LDAP request containing multiple . (dot) wildcard characters in …
|
NVD-CWE-noinfo
|
CVE-2009-2456
|
2017-08-17 10:30 |
2009-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260410
|
- |
|
novell
|
edirectory
|
The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial of service (crash) via a malformed bind LDAP packet.
|
CWE-94
Code Injection
|
CVE-2009-2457
|
2017-08-17 10:30 |
2009-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|