257601
|
- |
|
limny
|
limny
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Limny 2.0 allow remote attackers to (1) hijack the authentication of users or administrators for requests that change the email address o…
|
CWE-352
Origin Validation Error
|
CVE-2010-0709
|
2017-08-17 10:32 |
2010-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257602
|
- |
|
zenoss
|
zenoss
|
Multiple SQL injection vulnerabilities in zport/dmd/Events/getJSONEventsInfo in Zenoss 2.3.3, and other versions before 2.5, allow remote authenticated users to execute arbitrary SQL commands via the…
|
CWE-89
SQL Injection
|
CVE-2010-0712
|
2017-08-17 10:32 |
2010-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257603
|
- |
|
moinmo
|
moinmoin
|
The default configuration of cfg.packagepages_actions_excluded in MoinMoin before 1.8.7 does not prevent unsafe package actions, which has unspecified impact and attack vectors.
|
CWE-16
Configuration
|
CVE-2010-0717
|
2017-08-17 10:32 |
2010-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257604
|
- |
|
microsoft
|
windows_media_player
|
Buffer overflow in Microsoft Windows Media Player 9 and 11.0.5721.5145 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted .mpg file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-0718
|
2017-08-17 10:32 |
2010-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257605
|
- |
|
microsoft
|
windows_2000 windows_2003_server windows_7 windows_server_2008 windows_vista windows_xp
|
An unspecified API in Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 does not validate arguments, which allows local users to cause a denia…
|
CWE-20
Improper Input Validation
|
CVE-2010-0719
|
2017-08-17 10:32 |
2010-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257606
|
- |
|
systemsoftware
|
erotik_auktionshaus
|
SQL injection vulnerability in news.php in Erotik Auktionshaus allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2010-0720
|
2017-08-17 10:32 |
2010-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257607
|
- |
|
systemsoftware
|
auktionshaus_gelb
|
SQL injection vulnerability in news.php in Auktionshaus Gelb 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2010-0721
|
2017-08-17 10:32 |
2010-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257608
|
- |
|
mhproducts
|
php_auktion_pro
|
SQL injection vulnerability in news.php in Php Auktion Pro allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2010-0722
|
2017-08-17 10:32 |
2010-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257609
|
- |
|
mhproducts
|
ero_auktion
|
SQL injection vulnerability in news.php in Ero Auktion 2.0 and 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2010-0723
|
2017-08-17 10:32 |
2010-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257610
|
- |
|
freedesktop
|
policykit
|
pkexec.c in pkexec in libpolkit in PolicyKit 0.96 allows local users to determine the existence of arbitrary files via the argument.
|
CWE-200
Information Exposure
|
CVE-2010-0750
|
2017-08-17 10:32 |
2010-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|