|
347701
|
- |
|
fetchmail
|
fetchmail
|
Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory and possibly gain privileges via a negative index number as …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2001-1009
|
2011-02-16 14:00 |
2001-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347702
|
- |
|
fetchmail
|
fetchmail
|
fetchmailconf in fetchmail before 5.7.4 allows local users to overwrite files of other users via a symlink attack on temporary files.
|
CWE-59
Link Following
|
CVE-2001-1378
|
2011-02-16 14:00 |
2001-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347703
|
- |
|
fetchmail
|
fetchmail
|
fetchmail email client before 5.9.10 does not properly limit the maximum number of messages available, which allows a remote IMAP server to overwrite memory via a message count that exceeds the bound…
|
CWE-20
Improper Input Validation
|
CVE-2002-0146
|
2011-02-16 05:45 |
2002-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347704
|
- |
|
php
|
php
|
Multiple format string vulnerabilities in the phar extension in PHP 5.3 before 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) and possibly execute arbitrary…
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2010-2094
|
2011-01-26 15:48 |
2010-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347705
|
- |
|
typsoft
|
typsoft_ftp_server
|
Typsoft FTP Server 1.11, with "Sub Directory Include" enabled, allows remote attackers to cause a denial of service (crash) by sending multiple RETR commands. NOTE: it was later reported that 1.10 i…
|
CWE-399
Resource Management Errors
|
CVE-2005-3294
|
2011-01-26 14:00 |
2005-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347706
|
- |
|
wordpress
|
wordpress
|
WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-0682
|
2011-01-19 15:55 |
2010-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347707
|
- |
|
phpf1
|
max\'s_image_uploader
|
Unrestricted file upload vulnerability in maxImageUpload/index.php in PHP F1 Max's Image Uploader 1.0, when Apache is not configured to handle the mime-type for files with pjpeg or jpeg extensions, a…
|
NVD-CWE-Other
|
CVE-2010-0390
|
2011-01-12 14:00 |
2010-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347708
|
- |
|
phpf1
|
max\'s_image_uploader
|
Per: http://cwe.mitre.org/data/definitions/434.html
'CWE-434: Unrestricted Upload of File with Dangerous Type'
|
NVD-CWE-Other
|
CVE-2010-0390
|
2011-01-12 14:00 |
2010-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347709
|
- |
|
embarcadero
|
interbase_smp_2009
|
Multiple stack-based buffer overflows in Embarcadero Technologies InterBase SMP 2009 9.0.3.437 allow remote attackers to execute arbitrary code via unknown vectors involving crafted packets. NOTE: t…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-0391
|
2011-01-12 14:00 |
2010-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347710
|
- |
|
cisco
|
unified_meetingplace
|
Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.2, and possibly 5 does not properly validate SQL commands, which allows remote attackers to create, modify, or delete data in …
|
CWE-89
SQL Injection
|
CVE-2010-0139
|
2011-01-7 14:00 |
2010-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|