260791
|
- |
|
apple
|
safari
|
Apple Safari before 3.2.2 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attack…
|
CWE-287
Improper Authentication
|
CVE-2009-2058
|
2017-08-17 10:30 |
2009-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260792
|
- |
|
google
|
chrome
|
src/net/http/http_transaction_winhttp.cc in Google Chrome before 1.0.154.53 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a p…
|
CWE-287
Improper Authentication
|
CVE-2009-2060
|
2017-08-17 10:30 |
2009-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260793
|
- |
|
mozilla
|
firefox
|
Mozilla Firefox before 3.0.10 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's con…
|
CWE-310
Cryptographic Issues
|
CVE-2009-2061
|
2017-08-17 10:30 |
2009-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260794
|
- |
|
apple
|
safari
|
Apple Safari before 3.2.2 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context…
|
CWE-287
Improper Authentication
|
CVE-2009-2062
|
2017-08-17 10:30 |
2009-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260795
|
- |
|
opera
|
opera_browser
|
Opera, possibly before 9.25, processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's cont…
|
CWE-287
Improper Authentication
|
CVE-2009-2063
|
2017-08-17 10:30 |
2009-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260796
|
- |
|
mozilla
|
firefox
|
Mozilla Firefox 3.0.10, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary we…
|
CWE-287
Improper Authentication
|
CVE-2009-2065
|
2017-08-17 10:30 |
2009-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260797
|
- |
|
apple
|
safari
|
Apple Safari detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by…
|
CWE-287
Improper Authentication
|
CVE-2009-2066
|
2017-08-17 10:30 |
2009-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260798
|
- |
|
opera
|
opera
|
Google Chrome detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, b…
|
CWE-287
Improper Authentication
|
CVE-2009-2068
|
2017-08-17 10:30 |
2009-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260799
|
- |
|
cisco
|
wrt160n
|
Cross-site request forgery (CSRF) vulnerability in Linksys WRT160N wireless router hardware 1 and firmware 1.02.2 allows remote attackers to hijack the authentication of other users for unspecified r…
|
CWE-352
Origin Validation Error
|
CVE-2009-2073
|
2017-08-17 10:30 |
2009-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260800
|
- |
|
llnl
|
slurm
|
Simple Linux Utility for Resource Management (SLURM) 1.2 and 1.3 before 1.3.14 does not properly set supplementary groups before invoking (1) sbcast from the slurmd daemon or (2) strigger from the sl…
|
CWE-255
Credentials Management
|
CVE-2009-2084
|
2017-08-17 10:30 |
2009-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|