|
308691
|
- |
|
linux
|
linux_kernel
|
The fuse_ioctl_copy_user function in the ioctl handler in fs/fuse/file.c in the Linux kernel 2.6.29-rc1 through 2.6.30.y uses the wrong variable in an argument to the kunmap function, which allows lo…
|
NVD-CWE-Other
|
CVE-2009-4410
|
2012-03-19 13:00 |
2009-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308692
|
- |
|
linux
|
linux_kernel
|
The nfs_lock function in fs/nfs/file.c in the Linux kernel 2.6.9 does not properly remove POSIX locks on files that are setgid without group-execute permission, which allows local users to cause a de…
|
CWE-399
Resource Management Errors
|
CVE-2007-6733
|
2012-03-19 13:00 |
2010-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308693
|
- |
|
cacti
|
cacti
|
SQL injection vulnerability in graph.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via a crafted rra_id parameter in a GET request in conjunction with a va…
|
CWE-89
SQL Injection
|
CVE-2010-2092
|
2012-02-16 13:04 |
2010-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308694
|
- |
|
cacti
|
cacti
|
SQL injection vulnerability in templates_export.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via the export_item_id parameter.
|
CWE-89
SQL Injection
|
CVE-2010-1431
|
2012-02-16 13:02 |
2010-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308695
|
- |
|
hp
|
power_manager
|
Stack-based buffer overflow in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to execute arbitrary code via a long fileName parameter.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-3999
|
2012-02-14 12:49 |
2010-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308696
|
- |
|
cafuego
|
simple_document_management_system
|
Multiple SQL injection vulnerabilities in Simple Document Management System (SDMS) 2.0-CVS and earlier allow remote attackers to execute arbitrary SQL commands via the (1) folder_id parameter in list…
|
CWE-89
SQL Injection
|
CVE-2005-3877
|
2012-02-7 14:00 |
2005-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308697
|
- |
|
sitracker
|
support_incident_tracker
|
Multiple unspecified vulnerabilities in Salford Software Support Incident Tracker (SiT!) before 3.30 have unknown impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2007-5635
|
2012-02-2 14:00 |
2007-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308698
|
- |
|
kde
|
kdelibs
|
KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle atta…
|
CWE-310
Cryptographic Issues
|
CVE-2009-2702
|
2012-01-19 12:40 |
2009-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308699
|
- |
|
semanticscuttle
|
semanticscuttle
|
Multiple cross-site request forgery (CSRF) vulnerabilities in SemanticScuttle before 0.91 allow remote attackers to (1) hijack the authentication of administrators via unknown vectors or (2) hijack t…
|
CWE-352
Origin Validation Error
|
CVE-2009-0708
|
2012-01-5 14:00 |
2009-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308700
|
- |
|
xzeroscripts
|
xzero_community_classifieds
|
Cross-site scripting (XSS) vulnerability in index.php in XZero Community Classifieds 4.97.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the name of an uploaded file…
|
CWE-79
Cross-site Scripting
|
CVE-2009-2914
|
2011-12-29 14:00 |
2009-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|