|
291311
|
- |
|
mozilla
|
firefox seamonkey
|
Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-0357
|
2017-09-29 10:33 |
2009-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291312
|
- |
|
mozilla
|
firefox
|
Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1) no-store and (2) no-cache Cache-Control directives, which allows local users to obtain sensitive information by using the (a) back…
|
CWE-200
Information Exposure
|
CVE-2009-0358
|
2017-09-29 10:33 |
2009-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291313
|
- |
|
ubuntu
|
ubuntu_linux
|
nm-applet.conf in GNOME NetworkManager before 0.7.0.99 contains an incorrect deny setting, which allows local users to discover (1) network connection passwords and (2) pre-shared keys via calls to t…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-0365
|
2017-09-29 10:33 |
2009-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291314
|
- |
|
microsoft
|
internet_explorer
|
Microsoft Internet Explorer 7 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Cl…
|
NVD-CWE-Other
|
CVE-2009-0369
|
2017-09-29 10:33 |
2009-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291315
|
- |
|
ibm
|
aix
|
Multiple unspecified vulnerabilities in IBM AIX 5.2.0 through 6.1.2 allow local users to append data to arbitrary files, related to (1) rmsock and (2) rmsock64 not creating "secure log files."
|
NVD-CWE-noinfo
|
CVE-2009-0370
|
2017-09-29 10:33 |
2009-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291316
|
- |
|
sitexs_cms
|
sitexs_cms
|
Directory traversal vulnerability in post.php in SiteXS CMS 0.1.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the type parameter.
|
CWE-22
Path Traversal
|
CVE-2009-0371
|
2017-09-29 10:33 |
2009-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291317
|
- |
|
memht
|
memht_portal
|
Unrestricted file upload vulnerability in index.php in Miltenovik Manojlo MemHT Portal 4.0.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an execut…
|
CWE-20
Improper Input Validation
|
CVE-2009-0372
|
2017-09-29 10:33 |
2009-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291318
|
- |
|
elearningforce
|
flash_magazine_deluxe
|
SQL injection vulnerability in the ElearningForce Flash Magazine Deluxe (com_flashmagazinedeluxe) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mag_id parame…
|
CWE-89
SQL Injection
|
CVE-2009-0373
|
2017-09-29 10:33 |
2009-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291319
|
- |
|
joomla
|
com_pcchess
|
SQL injection vulnerability in the Prince Clan Chess Club (com_pcchess) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the game_id parameter in a showgame action …
|
CWE-89
SQL Injection
|
CVE-2009-0379
|
2017-09-29 10:33 |
2009-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291320
|
- |
|
bazaarbuilder
|
ecommerce_shopping_cart
|
SQL injection vulnerability in the BazaarBuilder Ecommerce Shopping Cart (com_prod) 5.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in a prod…
|
CWE-89
SQL Injection
|
CVE-2009-0381
|
2017-09-29 10:33 |
2009-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|