256411
|
- |
|
collector
|
mygesuad
|
modules/admuser.php in myGesuad 0.9.14 (aka 0.9) does not require administrative authentication, which allows remote authenticated users to list user accounts via a Find action.
|
CWE-287
Improper Authentication
|
CVE-2009-1826
|
2017-09-29 10:34 |
2009-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256412
|
- |
|
wireshark
|
wireshark
|
Unspecified vulnerability in the PCNFSD dissector in Wireshark 0.8.20 through 1.0.7 allows remote attackers to cause a denial of service (crash) via crafted PCNFSD packets.
|
NVD-CWE-noinfo
|
CVE-2009-1829
|
2017-09-29 10:34 |
2009-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256413
|
- |
|
slsknet
|
soulseek
|
Stack-based buffer overflow in Soulseek 156 and 157 NS allows remote attackers to execute arbitrary code via a long search query.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-1830
|
2017-09-29 10:34 |
2009-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256414
|
- |
|
nullsoft
|
winamp
|
The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute arbitrary code via a crafted MAKI file, which triggers an incorrect sign exten…
|
CWE-189
Numeric Errors
|
CVE-2009-1831
|
2017-09-29 10:34 |
2009-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256415
|
- |
|
mozilla
|
firefox
|
Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote attackers to bypass intended access restrictions …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-1839
|
2017-09-29 10:34 |
2009-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256416
|
- |
|
mozilla
|
firefox seamonkey thunderbird
|
Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote attackers to bypass intended access restric…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-1840
|
2017-09-29 10:34 |
2009-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256417
|
- |
|
bjsintay
|
sitex
|
Multiple directory traversal vulnerabilities in SiteX 0.7.4 Build 418 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the THEME_FOLDER parameter …
|
CWE-22
Path Traversal
|
CVE-2009-1846
|
2017-09-29 10:34 |
2009-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256418
|
- |
|
easypx41
|
easy_px_41_cms
|
Directory traversal vulnerability in index.php in Easy PX 41 CMS 9.0 B1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the fiche parameter.
|
CWE-22
Path Traversal
|
CVE-2009-1847
|
2017-09-29 10:34 |
2009-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256419
|
- |
|
joomlame
|
com_agoragroup
|
SQL injection vulnerability in the JoomlaMe AgoraGroups (aka AG or com_agoragroup) component 0.3.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a gr…
|
CWE-89
SQL Injection
|
CVE-2009-1848
|
2017-09-29 10:34 |
2009-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256420
|
- |
|
benjamin_curtis
|
phpbugtracker
|
SQL injection vulnerability in index.php in phpBugTracker 1.0.3 allows remote attackers to execute arbitrary SQL commands via the password parameter.
|
CWE-89
SQL Injection
|
CVE-2009-1850
|
2017-09-29 10:34 |
2009-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|