256981
|
- |
|
yaws
|
yaws
|
Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of headers.
|
CWE-399
Resource Management Errors
|
CVE-2009-0751
|
2017-09-29 10:34 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256982
|
- |
|
mldonkey
|
mldonkey
|
Absolute path traversal vulnerability in MLDonkey 2.8.4 through 2.9.7 allows remote attackers to read arbitrary files via a leading "//" (double slash) in the filename.
|
CWE-22
Path Traversal
|
CVE-2009-0753
|
2017-09-29 10:34 |
2009-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256983
|
- |
|
team5
|
team_board
|
Team Board 1.x and 2.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct reque…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-0760
|
2017-09-29 10:34 |
2009-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256984
|
- |
|
team5.team_board
|
1.0 1.0.1 1.0.2 1.0.3 1.0.4 1.0.5
|
Cross-site scripting (XSS) vulnerability in online.asp in Team Board 1.x allows remote attackers to inject arbitrary web script or HTML via the lookname parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-0761
|
2017-09-29 10:34 |
2009-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256985
|
- |
|
bookelves
|
kipper
|
Cross-site scripting (XSS) vulnerability in default.php in Kipper 2.01 allows remote attackers to inject arbitrary web script or HTML via the charm parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-0763
|
2017-09-29 10:34 |
2009-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256986
|
- |
|
bookelves
|
kipper
|
Directory traversal vulnerability in index.php in Kipper 2.01 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the configfile parameter.
|
CWE-22
Path Traversal
|
CVE-2009-0765
|
2017-09-29 10:34 |
2009-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256987
|
- |
|
bookelves
|
kipper
|
Kipper 2.01 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing credentials via a direct request for job/conf…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-0767
|
2017-09-29 10:34 |
2009-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256988
|
- |
|
yapbb
|
yapbb
|
SQL injection vulnerability in forumhop.php in YapBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the forumID parameter in a next action.
|
CWE-89
SQL Injection
|
CVE-2009-0768
|
2017-09-29 10:34 |
2009-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256989
|
- |
|
mozilla
|
firefox seamonkey thunderbird
|
The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary co…
|
CWE-399
Resource Management Errors
|
CVE-2009-0773
|
2017-09-29 10:34 |
2009-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256990
|
- |
|
mozilla
|
firefox seamonkey thunderbird
|
Double free vulnerability in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to execute arbitrary code via "cloned XUL DOM elements whic…
|
CWE-399
Resource Management Errors
|
CVE-2009-0775
|
2017-09-29 10:34 |
2009-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|