|
348621
|
- |
|
emc
|
networker
|
EMC NetWorker (formerly Legato NetWorker) before 7.0 stores log files in the /nsr/logs/ directory with world-readable permissions, which allows local users to read sensitive information and possibly …
|
NVD-CWE-Other
|
CVE-2002-0113
|
2012-03-30 10:14 |
2002-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348622
|
- |
|
emc
|
networker
|
EMC NetWorker (formerly Legato NetWorker) before 7.0 stores passwords in plaintext in the daemon.log file, which allows local users to gain privileges by reading the password from the file. NOTE: th…
|
NVD-CWE-Other
|
CVE-2002-0114
|
2012-03-30 10:14 |
2002-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348623
|
- |
|
linux
|
linux_kernel
|
The nfs_lock function in fs/nfs/file.c in the Linux kernel 2.6.9 does not properly remove POSIX locks on files that are setgid without group-execute permission, which allows local users to cause a de…
|
CWE-399
Resource Management Errors
|
CVE-2007-6733
|
2012-03-19 13:00 |
2010-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348624
|
- |
|
cacti
|
cacti
|
SQL injection vulnerability in graph.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via a crafted rra_id parameter in a GET request in conjunction with a va…
|
CWE-89
SQL Injection
|
CVE-2010-2092
|
2012-02-16 13:04 |
2010-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348625
|
- |
|
cacti
|
cacti
|
SQL injection vulnerability in templates_export.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via the export_item_id parameter.
|
CWE-89
SQL Injection
|
CVE-2010-1431
|
2012-02-16 13:02 |
2010-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348626
|
- |
|
hp
|
power_manager
|
Stack-based buffer overflow in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to execute arbitrary code via a long fileName parameter.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-3999
|
2012-02-14 12:49 |
2010-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348627
|
- |
|
cafuego
|
simple_document_management_system
|
Multiple SQL injection vulnerabilities in Simple Document Management System (SDMS) 2.0-CVS and earlier allow remote attackers to execute arbitrary SQL commands via the (1) folder_id parameter in list…
|
CWE-89
SQL Injection
|
CVE-2005-3877
|
2012-02-7 14:00 |
2005-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348628
|
- |
|
plume-cms
|
plume_cms
|
Multiple PHP remote file inclusion vulnerabilities in Plume CMS 1.0.6 and earlier allow remote attackers to execute arbitrary PHP code via the _PX_config[manager_path] parameter to (1) articles.php, …
|
CWE-94
Code Injection
|
CVE-2006-4533
|
2011-11-10 14:00 |
2006-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348629
|
- |
|
ffmpeg
|
ffmpeg
|
oggparsevorbis.c in FFmpeg 0.5 does not properly perform certain pointer arithmetic, which might allow remote attackers to obtain sensitive memory contents and cause a denial of service via a crafted…
|
CWE-189
Numeric Errors
|
CVE-2009-4632
|
2011-10-26 11:44 |
2010-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348630
|
- |
|
ffmpeg
|
ffmpeg
|
vorbis_dec.c in FFmpeg 0.5 uses an assignment operator when a comparison operator was intended, which might allow remote attackers to cause a denial of service and possibly execute arbitrary code via…
|
CWE-189
Numeric Errors
|
CVE-2009-4633
|
2011-10-26 11:44 |
2010-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|