|
278221
|
- |
|
opera
|
opera_browser
|
Opera before 10.00 trusts root X.509 certificates signed with the MD2 algorithm, which makes it easier for man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted server certificate.
|
CWE-310
Cryptographic Issues
|
CVE-2009-3045
|
2018-10-31 01:26 |
2009-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278222
|
- |
|
opera
|
opera_browser
|
Opera before 10.00, when a collapsed address bar is used, does not properly update the domain name from the previously visited site to the currently visited site, which might allow remote attackers t…
|
NVD-CWE-Other
|
CVE-2009-3047
|
2018-10-31 01:26 |
2009-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278223
|
- |
|
opera
|
opera_browser
|
Opera before 10.00 does not properly display all characters in Internationalized Domain Names (IDN) in the address bar, which allows remote attackers to spoof URLs and conduct phishing attacks, relat…
|
NVD-CWE-Other
|
CVE-2009-3049
|
2018-10-31 01:26 |
2009-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278224
|
- |
|
opera
|
opera_browser
|
Opera before 10.01 does not properly restrict HTML in a (1) RSS or (2) Atom feed, which allows remote attackers to conduct cross-site scripting (XSS) attacks, and conduct cross-zone scripting attacks…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3266
|
2018-10-31 01:26 |
2009-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278225
|
- |
|
php
|
php
|
The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability t…
|
CWE-20
Improper Input Validation
|
CVE-2009-3291
|
2018-10-31 01:26 |
2009-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278226
|
- |
|
php
|
php
|
Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."
|
NVD-CWE-noinfo
|
CVE-2009-3292
|
2018-10-31 01:26 |
2009-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278227
|
- |
|
php
|
php
|
Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."
|
NVD-CWE-noinfo
|
CVE-2009-3293
|
2018-10-31 01:26 |
2009-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278228
|
- |
|
php
|
php
|
The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass safe_mode restrictions, and create files in group-writable or worl…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-3557
|
2018-10-31 01:26 |
2009-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278229
|
- |
|
php
|
php
|
The posix_mkfifo function in ext/posix/posix.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass open_basedir restrictions, and create FIFO files, via the pathn…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-3558
|
2018-10-31 01:26 |
2009-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278230
|
- |
|
php
|
php
|
Access Complexity selected medium according to the information from X-force link regarding enabling "open_basedir" option.
http://xforce.iss.net/xforce/xfdb/53568
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-3558
|
2018-10-31 01:26 |
2009-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|