261721
|
- |
|
ubuntu
|
linux
|
Per https://bugs.launchpad.net/ubuntu/+source/clamav/+bug/365823
A clean install of clamav-milter (0.95.1+dfsg-1ubuntu1.1) causes the root directory to become owned by the clamav user.
This was…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-1601
|
2017-08-17 10:30 |
2009-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261722
|
- |
|
dafolo
|
dafolocontrol
|
Multiple stack-based and heap-based buffer overflows in Dafolo DafoloControl ActiveX control (DafoloFFControl.dll) 1.108.6.195 allow remote attackers to execute arbitrary code via long (1) baseurl, (…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-1606
|
2017-08-17 10:30 |
2009-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261723
|
- |
|
novell
|
groupwise
|
The WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 does not properly implement session management mechanisms, which allows remote attackers to gain access to user …
|
NVD-CWE-Other
|
CVE-2009-1634
|
2017-08-17 10:30 |
2009-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261724
|
- |
|
xerox
|
workcentre
|
Xerox WorkCentre and WorkCentre Pro 232, 238, 245, 255, 265, 275; and WorkCentre 5632, 5638, 5645, 5655, 5665, 5675, 5687, 7655, 7656, and 7675 allows remote attackers to execute arbitrary commands v…
|
NVD-CWE-Other
|
CVE-2009-1656
|
2017-08-17 10:30 |
2009-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261725
|
- |
|
b2evolution
|
starrating_plugin
|
Multiple SQL injection vulnerabilities in the Starrating plugin before 0.7.7 for b2evolution allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2009-1657
|
2017-08-17 10:30 |
2009-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261726
|
- |
|
apple
|
safari
|
WebKit in Apple Safari before 4.0 allows remote attackers to spoof the browser's display of (1) the host name, (2) security indicators, and unspecified other UI elements via a custom cursor in conjun…
|
NVD-CWE-Other
|
CVE-2009-1710
|
2017-08-17 10:30 |
2009-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261727
|
- |
|
apple
|
safari
|
WebKit in Apple Safari before 4.0 does not properly initialize memory for Attr DOM objects, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) vi…
|
CWE-399
Resource Management Errors
|
CVE-2009-1711
|
2017-08-17 10:30 |
2009-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261728
|
- |
|
apple
|
safari
|
WebKit in Apple Safari before 4.0 does not prevent remote loading of local Java applets, which allows remote attackers to execute arbitrary code, gain privileges, or obtain sensitive information via …
|
CWE-94
Code Injection
|
CVE-2009-1712
|
2017-08-17 10:30 |
2009-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261729
|
- |
|
apple
|
safari
|
The XSLT functionality in WebKit in Apple Safari before 4.0 does not properly implement the document function, which allows remote attackers to read (1) arbitrary local files and (2) files from diffe…
|
CWE-200
Information Exposure
|
CVE-2009-1713
|
2017-08-17 10:30 |
2009-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261730
|
- |
|
apple
|
safari
|
Cross-site scripting (XSS) vulnerability in Web Inspector in WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to inject arbitrary web script or HTML, and read local files, via …
|
CWE-79
Cross-site Scripting
|
CVE-2009-1714
|
2017-08-17 10:30 |
2009-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|