|
314491
|
9.8 |
CRITICAL
Network
|
risearch
|
risearch risearch_pro
|
RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, o…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2004-2061
|
2024-02-9 04:56 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314492
|
9.8 |
CRITICAL
Network
|
siemens
|
db4web
|
DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that sp…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2002-1484
|
2024-02-9 04:56 |
2003-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314493
|
7.5 |
HIGH
Network
|
adobe
|
acrobat_reader acrobat
|
The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulne…
|
CWE-611
XXE
|
CVE-2005-1306
|
2024-02-9 04:55 |
2005-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314494
|
5.5 |
MEDIUM
Local
|
dump_project
|
dump
|
dump 0.4 b10 through b29 allows local users to cause a denial of service (execution prevention) by using flock() to lock the /etc/dumpdates file.
|
CWE-667
Improper Locking
|
CVE-2002-1914
|
2024-02-9 04:24 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314495
|
5.5 |
MEDIUM
Local
|
openbsd netbsd freebsd
|
openbsd netbsd freebsd
|
tip on multiple BSD-based operating systems allows local users to cause a denial of service (execution prevention) by using flock() to lock the /var/log/acculog file.
|
CWE-667
Improper Locking
|
CVE-2002-1915
|
2024-02-9 04:24 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314496
|
7.8 |
HIGH
Local
|
microsoft
|
windows_2000
|
Windows 2000 allows local users to prevent the application of new group policy settings by opening Group Policy files with exclusive-read access.
|
CWE-667
Improper Locking
|
CVE-2002-0051
|
2024-02-9 04:24 |
2002-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314497
|
5.5 |
MEDIUM
Local
|
concurrent_versions_software_project
|
concurrent_versions_software
|
Concurrent Versions Software (CVS) uses predictable temporary file names for locking, which allows local users to cause a denial of service by creating the lock directory before it is created for use…
|
CWE-667
Improper Locking
|
CVE-2000-0338
|
2024-02-9 04:23 |
2000-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314498
|
5.5 |
MEDIUM
Local
|
qualcomm
|
qpopper
|
qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files for other mail boxes.
|
CWE-667
Improper Locking
|
CVE-2000-1198
|
2024-02-9 04:22 |
2001-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314499
|
9.8 |
CRITICAL
Network
|
gnome debian
|
evolution debian_linux
|
Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2005-0102
|
2024-02-9 03:39 |
2005-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314500
|
9.8 |
CRITICAL
Network
|
php opensuse suse
|
php opensuse linux_enterprise
|
The dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked encoding stream, allows context-dependent attackers to cause a denial of service (crash) and possibly trigger memory corrupt…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2010-1866
|
2024-02-9 03:38 |
2010-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|