258521
|
- |
|
tim_hockin
|
acpid
|
A certain Red Hat patch for acpid 1.0.4 effectively triggers a call to the open function with insufficient arguments, which might allow local users to leverage weak permissions on /var/log/acpid, and…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-4033
|
2017-09-19 10:29 |
2009-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258522
|
- |
|
gnome kde xpdf
|
gpdf kdegraphics kpdf xpdf
|
The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine …
|
CWE-94
Code Injection
|
CVE-2009-4035
|
2017-09-19 10:29 |
2009-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258523
|
- |
|
ohloh
|
agoko_cms
|
Unrestricted file upload vulnerability in admintools/editpage-2.php in Agoko CMS 0.4 and earlier allows remote attackers to inject and execute arbitrary PHP code via the filename and text parameters.
|
CWE-20
Improper Input Validation
|
CVE-2009-4106
|
2017-09-19 10:29 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258524
|
- |
|
amplusnet
|
invisible_browsing
|
Buffer overflow in Invisible Browsing 5.0.52 allows user-assisted remote attackers to execute arbitrary code via a crafted .ibkey file containing a long string.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-4107
|
2017-09-19 10:29 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258525
|
- |
|
gnome
|
networkmanager
|
NetworkManager (NM) 0.7.2 does not ensure that the configured Certification Authority (CA) certificate file for a (1) WPA Enterprise or (2) 802.1x network remains present upon a connection attempt, w…
|
CWE-310
Cryptographic Issues
|
CVE-2009-4144
|
2017-09-19 10:29 |
2009-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258526
|
- |
|
gnome
|
networkmanager
|
nm-connection-editor in NetworkManager (NM) 0.7.x exports connection objects over D-Bus upon actions in the connection editor GUI, which allows local users to obtain sensitive information by reading …
|
CWE-200
Information Exposure
|
CVE-2009-4145
|
2017-09-19 10:29 |
2009-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258527
|
- |
|
hp
|
enterprise_cluster_master_toolkit
|
Unspecified vulnerability in HP Enterprise Cluster Master Toolkit (ECMT) B.05.00 on HP-UX B.11.23 (11i v2) and HP-UX B.11.31 (11i v3) allows local users to gain access to an Oracle or Sybase database…
|
NVD-CWE-noinfo
|
CVE-2009-4184
|
2017-09-19 10:29 |
2010-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258528
|
- |
|
cupidsystems
|
myminibill
|
SQL injection vulnerability in my_orders.php in MyMiniBill allows remote authenticated users to execute arbitrary SQL commands via the orderid parameter in a status action.
|
CWE-89
SQL Injection
|
CVE-2009-4198
|
2017-09-19 10:29 |
2009-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258529
|
- |
|
mamboforge
|
com_mosres
|
Multiple SQL injection vulnerabilities in the Mambo Resident (aka Mos Res or com_mosres) component 1.0f for Mambo and Joomla!, when magic_quotes_gpc is disabled, allow remote attackers to execute arb…
|
CWE-89
SQL Injection
|
CVE-2009-4199
|
2017-09-19 10:29 |
2009-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258530
|
- |
|
vollmar
|
com_seminar
|
SQL injection vulnerability in the Seminar (com_seminar) component 1.28 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a View_seminar action to index.ph…
|
CWE-89
SQL Injection
|
CVE-2009-4200
|
2017-09-19 10:29 |
2009-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|