263091
|
- |
|
apple
|
safari
|
The XSLT functionality in WebKit in Apple Safari before 4.0 does not properly implement the document function, which allows remote attackers to read (1) arbitrary local files and (2) files from diffe…
|
CWE-200
Information Exposure
|
CVE-2009-1713
|
2017-08-17 10:30 |
2009-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263092
|
- |
|
apple
|
safari
|
Cross-site scripting (XSS) vulnerability in Web Inspector in WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to inject arbitrary web script or HTML, and read local files, via …
|
CWE-79
Cross-site Scripting
|
CVE-2009-1714
|
2017-08-17 10:30 |
2009-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263093
|
- |
|
apple
|
mac_os_x mac_os_x_server
|
CFNetwork in Apple Mac OS X 10.5 before 10.5.8 places an incorrect URL in a certificate warning in certain 302 redirection scenarios, which makes it easier for remote attackers to trick a user into v…
|
NVD-CWE-Other
|
CVE-2009-1723
|
2017-08-17 10:30 |
2009-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263094
|
- |
|
apple
|
mac_os_x mac_os_x_server
|
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X 10.5 before 10.5.8 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a do…
|
NVD-CWE-Other
|
CVE-2009-1727
|
2017-08-17 10:30 |
2009-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263095
|
- |
|
apple
|
mac_os_x mac_os_x_server
|
Stack-based buffer overflow in Image RAW in Apple Mac OS X 10.5 before 10.5.8, and 10.4 before Digital Camera RAW Compatibility Update 2.6, allows remote attackers to execute arbitrary code or cause …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-1728
|
2017-08-17 10:30 |
2009-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263096
|
- |
|
mlffat
|
mlffat
|
SQL injection vulnerability in panel/index.php in MLFFAT 2.1 allows remote attackers to execute arbitrary SQL commands via a base64-encoded supervisor cookie.
|
CWE-89
SQL Injection
|
CVE-2009-1731
|
2017-08-17 10:30 |
2009-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263097
|
- |
|
richard_ellerbrock
|
ipplan
|
Cross-site request forgery (CSRF) vulnerability in IPplan 4.91a allows remote attackers to hijack the authentication of administrators for requests that (1) change the password, (2) add users, or (3)…
|
CWE-352
Origin Validation Error
|
CVE-2009-1733
|
2017-08-17 10:30 |
2009-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263098
|
- |
|
diqiye
|
mypic
|
Directory traversal vulnerability in bom.php in MyPic 2.1 allows remote attackers to list files in arbitrary directories via a .. (dot dot) in the dir parameter.
|
CWE-22
Path Traversal
|
CVE-2009-1737
|
2017-08-17 10:30 |
2009-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263099
|
- |
|
ivanjaros
|
feed_block
|
Cross-site scripting (XSS) vulnerability in Feed Block 6.x-1.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with administrator feed permissions to inject arbitrary web scrip…
|
CWE-79
Cross-site Scripting
|
CVE-2009-1738
|
2017-08-17 10:30 |
2009-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263100
|
- |
|
dlink
|
mpeg4_viewer_activex_control
|
Multiple heap-based buffer overflows in the D-Link MPEG4 Viewer ActiveX Control (csviewer.ocx) 2.11.918.2006 allow remote attackers to execute arbitrary code via a long argument to the (1) SetFilePat…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-1740
|
2017-08-17 10:30 |
2009-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|