260641
|
- |
|
sun
|
java_system_identity_manager
|
Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not properly restrict access to the System Configuration object, which allows remote authenticated administrators and possibly remote attac…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-1084
|
2017-08-17 10:30 |
2009-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260642
|
- |
|
cisco
|
ironport_asyncos ironport_email_security_appliances
|
Cross-site scripting (XSS) vulnerability in the Spam Quarantine login page in Cisco IronPort AsyncOS before 6.5.2 on Series C, M, and X appliances allows remote attackers to inject arbitrary web scri…
|
CWE-79
Cross-site Scripting
|
CVE-2009-1162
|
2017-08-17 10:30 |
2009-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260643
|
- |
|
sun
|
opensolaris
|
Unspecified vulnerability in Sun OpenSolaris snv_100 through snv_101 allows local users, with privileges in a non-global zone, to execute arbitrary code in the global zone when a global-zone user is …
|
NVD-CWE-noinfo
|
CVE-2009-1170
|
2017-08-17 10:30 |
2009-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260644
|
- |
|
futomi
|
cgi_cafe_access_analyzer_cgi
|
Unspecified vulnerability in futomi's CGI Cafe Access Analyzer CGI Professional Version 4.11.5 and earlier allows remote attackers to gain administrative privileges via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2009-1206
|
2017-08-17 10:30 |
2009-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260645
|
- |
|
auth2db auth2dbauth2db
|
auth2db 0.1.1
|
SQL injection vulnerability in auth2db 0.2.5, and possibly other versions before 0.2.7, uses the addslashes function instead of the mysql_real_escape_string function, which allows remote attackers to…
|
CWE-89
SQL Injection
|
CVE-2009-1208
|
2017-08-17 10:30 |
2009-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260646
|
- |
|
mozilla
|
bugzilla
|
Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 3.2 before 3.2.3, 3.3 before 3.3.4, and earlier versions allows remote attackers to hijack the authentication of arbitrar…
|
CWE-352
Origin Validation Error
|
CVE-2009-1213
|
2017-08-17 10:30 |
2009-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260647
|
- |
|
gnu
|
screen
|
GNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-readable permissions, which might allow local users to obtain sensitive session information.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-1214
|
2017-08-17 10:30 |
2009-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260648
|
- |
|
gnu
|
gnu_screen
|
Race condition in GNU screen 4.0.3 allows local users to create or overwrite arbitrary files via a symlink attack on the /tmp/screen-exchange temporary file.
|
CWE-362
Race Condition
|
CVE-2009-1215
|
2017-08-17 10:30 |
2009-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260649
|
- |
|
ibm
|
db2
|
IBM DB2 9.1 before FP7 returns incorrect query results in certain situations related to the order of application of an INNER JOIN predicate and an OUTER JOIN predicate, which might allow attackers to…
|
CWE-200
Information Exposure
|
CVE-2009-1239
|
2017-08-17 10:30 |
2009-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260650
|
- |
|
cccp-common-clan-portal-pasterbin
|
cccp_pastebin
|
Multiple SQL injection vulnerabilities in the insert_to_pastebin function in php/cccp-admin/inc/functions.php in CCCP Community Clan Portal Pastebin before 2.80 allow remote attackers to execute arbi…
|
CWE-89
SQL Injection
|
CVE-2009-1245
|
2017-08-17 10:30 |
2009-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|