|
291161
|
- |
|
pidgin
|
pidgin
|
The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote attackers to cause a denial of service (applicati…
|
CWE-399
Resource Management Errors
|
CVE-2009-1889
|
2017-09-29 10:34 |
2009-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291162
|
- |
|
ruby-lang
|
ruby
|
The BigDecimal library in Ruby 1.8.6 before p369 and 1.8.7 before p173 allows context-dependent attackers to cause a denial of service (application crash) via a string argument that represents a larg…
|
CWE-189
Numeric Errors
|
CVE-2009-1904
|
2017-09-29 10:34 |
2009-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291163
|
- |
|
webspell
|
webspell
|
Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arbitrary local .php files via a .. (dot dot) in a language co…
|
CWE-22
Path Traversal
|
CVE-2009-1912
|
2017-09-29 10:34 |
2009-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291164
|
- |
|
luxbum
|
luxbum
|
SQL injection vulnerability in manager.php in LuxBum 0.5.5, when magic_quotes_gpc is disabled and dotclear authentication is used, allows remote attackers to execute arbitrary SQL commands via the us…
|
CWE-89
SQL Injection
|
CVE-2009-1913
|
2017-09-29 10:34 |
2009-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291165
|
- |
|
gscripts
|
dns_tools
|
dig.php in GScripts.net DNS Tools allows remote attackers to execute arbitrary commands via shell metacharacters in the ns parameter.
|
CWE-78
OS Command
|
CVE-2009-1916
|
2017-09-29 10:34 |
2009-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291166
|
- |
|
gstreamer
|
good_plug-ins
|
Multiple integer overflows in the (1) user_info_callback, (2) user_endrow_callback, and (3) gst_pngdec_task functions (ext/libpng/gstpngdec.c) in GStreamer Good Plug-ins (aka gst-plugins-good or gstr…
|
CWE-189
Numeric Errors
|
CVE-2009-1932
|
2017-09-29 10:34 |
2009-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291167
|
- |
|
phpeasycode
|
pad_site_scripts
|
PAD Site Scripts 3.6 stores sensitive information under the web document root with insufficient access control, which allows remote attackers to download the database and obtain sensitive information…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-1941
|
2017-09-29 10:34 |
2009-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291168
|
- |
|
aimp
|
aimp
|
Stack-based buffer overflow in AIMP 2.51 build 330 allows remote attackers to execute arbitrary code via an MP3 file with a long ID3 tag.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-1944
|
2017-09-29 10:34 |
2009-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291169
|
- |
|
tzo
|
webcal
|
SQL injection vulnerability in webCal3_detail.asp in WebCal 3.04 allows remote attackers to execute arbitrary SQL commands via the event_id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-1945
|
2017-09-29 10:34 |
2009-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291170
|
- |
|
adaptbb
|
adaptbb
|
PHP remote file inclusion vulnerability in latestposts.php in AdaptBB 1.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the forumspath paramete…
|
CWE-94
Code Injection
|
CVE-2009-1946
|
2017-09-29 10:34 |
2009-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|