|
346961
|
- |
|
gnu
|
gzip
|
The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infi…
|
CWE-20
Improper Input Validation
|
CVE-2009-2624
|
2010-11-18 15:29 |
2010-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346962
|
- |
|
sterlitetechnologies
|
sam300_ax_router
|
Cross-site scripting (XSS) vulnerability in Forms/status_statistics_1 in the Sterlite SAM300 AX Router allows remote attackers to inject arbitrary web script or HTML via the Stat_Radio parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2010-0607
|
2010-11-4 13:00 |
2010-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346963
|
- |
|
osticket
|
osticket
|
Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitrary web script or HTML via the f parameter, possibly related…
|
CWE-79
Cross-site Scripting
|
CVE-2010-0606
|
2010-11-4 03:16 |
2010-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346964
|
- |
|
novaboard
|
novaboard
|
SQL injection vulnerability in header.php in NovaBoard 1.1.2 allows remote attackers to execute arbitrary SQL commands via the nova_name cookie parameter. NOTE: the provenance of this information is…
|
CWE-89
SQL Injection
|
CVE-2010-0609
|
2010-11-4 02:46 |
2010-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346965
|
- |
|
ibm
|
websphere_application_server
|
The Single Sign-on (SSO) functionality in IBM WebSphere Application Server (WAS) 7.0.0.0 through 7.0.0.8 does not recognize the Requires SSL configuration option, which might allow remote attackers t…
|
CWE-200
Information Exposure
|
CVE-2010-0563
|
2010-11-3 13:00 |
2010-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346966
|
- |
|
opera
|
opera_browser
|
Opera before 10.10 permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers…
|
CWE-200
Information Exposure
|
CVE-2010-0653
|
2010-09-21 14:46 |
2010-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346967
|
- |
|
fujitsu
|
e-pares
|
Session fixation vulnerability in Fujitsu e-Pares V01 L01, L03, L10, L20, L30 allows remote attackers to hijack web sessions via unspecified vectors.
|
CWE-287
Improper Authentication
|
CVE-2010-2149
|
2010-09-21 13:00 |
2010-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346968
|
- |
|
php_group
|
php
|
Unspecified vulnerability in the session extension functionality in PHP before 5.1.3 has unknown impact and attack vectors related to heap corruption.
|
NVD-CWE-Other
|
CVE-2006-3018
|
2010-09-15 13:54 |
2006-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346969
|
- |
|
mono
|
mono
|
The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as dem…
|
CWE-79
Cross-site Scripting
|
CVE-2010-1459
|
2010-09-9 14:41 |
2010-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346970
|
- |
|
otrs
|
otrs
|
Multiple SQL injection vulnerabilities in Kernel/System/Ticket.pm in OTRS-Core in Open Ticket Request System (OTRS) 2.1.x before 2.1.9, 2.2.x before 2.2.9, 2.3.x before 2.3.5, and 2.4.x before 2.4.7 …
|
CWE-89
SQL Injection
|
CVE-2010-0438
|
2010-09-9 14:39 |
2010-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|