261621
|
- |
|
nanosleep
|
trac-git
|
PyGIT.py in the Trac Git plugin (trac-git) before 0.0.20080710-3+lenny1 and before 0.0.20090320-1 on Debian GNU/Linux, when enabled in Trac, allows remote attackers to execute arbitrary commands via …
|
CWE-20
Improper Input Validation
|
CVE-2010-0394
|
2017-08-17 10:31 |
2010-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261622
|
- |
|
debian
|
dpkg
|
Directory traversal vulnerability in the dpkg-source component in dpkg before 1.14.29 allows remote attackers to modify arbitrary files via a crafted Debian source archive.
|
CWE-22
Path Traversal
|
CVE-2010-0396
|
2017-08-17 10:31 |
2010-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261623
|
- |
|
gnome
|
screensaver
|
gnome-screensaver 2.28.x before 2.28.3 does not properly synchronize the state of screen locking and the unlock dialog in situations involving a change to the number of monitors, which allows physica…
|
NVD-CWE-Other
|
CVE-2010-0422
|
2017-08-17 10:31 |
2010-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261624
|
- |
|
flock mozilla
|
flock firefox seamonkey
|
Mozilla Firefox 3.5.1 and SeaMonkey 1.1.17, and Flock 2.5.1, allow context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a vi…
|
NVD-CWE-Other
|
CVE-2009-3007
|
2017-08-17 10:31 |
2009-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261625
|
- |
|
christophe_thibault
|
k-meleon
|
K-Meleon 1.5.3 allows context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a victim has visited any file: URL, as demonstrat…
|
NVD-CWE-Other
|
CVE-2009-3008
|
2017-08-17 10:31 |
2009-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261626
|
- |
|
google
|
chrome
|
Google Chrome 1.0.154.48 and earlier, 2.0.172.28, 2.0.172.37, and 3.0.193.2 Beta does not properly block data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cros…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3011
|
2017-08-17 10:31 |
2009-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261627
|
- |
|
qtweb
|
qtweb
|
QtWeb 3.0 Builds 001 and 003 does not properly block javascript: and data: URIs in Refresh and Location headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) …
|
CWE-79
Cross-site Scripting
|
CVE-2009-3015
|
2017-08-17 10:31 |
2009-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261628
|
- |
|
symantec
|
securityexpressions_audit_and_compliance_server
|
Cross-site scripting (XSS) vulnerability in Symantec SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and earlier allows remote attackers to inject arbitrary web script or HTML via vectors…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3030
|
2017-08-17 10:31 |
2009-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261629
|
- |
|
symantec
|
altiris_deployment_solution altiris_management_platform altiris_notification_server
|
Buffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web console in Symantec Altiris Deployment Solution 6.9.x, Altiris…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-3033
|
2017-08-17 10:31 |
2009-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261630
|
- |
|
symantec
|
altiris_notification_server
|
The web console in Symantec Altiris Notification Server 6.0.x before 6.0 SP3 R12 uses a hardcoded key that can decrypt SQL Server credentials and certain discovery credentials, and stores this key on…
|
CWE-255
Credentials Management
|
CVE-2009-3035
|
2017-08-17 10:31 |
2010-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|