|
287551
|
- |
|
geopp
|
geo\+\+_gncaster
|
Geo++ GNCASTER 1.4.0.7 and earlier allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a long NMEA data sentence.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-0553
|
2018-10-11 04:53 |
2010-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287552
|
- |
|
geopp
|
geo\+\+_gncaster
|
The HTTP Authentication implementation in Geo++ GNCASTER 1.4.0.7 and earlier uses the same nonce for all authentication, which allows remote attackers to hijack web sessions or bypass authentication …
|
CWE-287
Improper Authentication
|
CVE-2010-0554
|
2018-10-11 04:53 |
2010-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287553
|
- |
|
google
|
chrome
|
browser/login/login_prompt.cc in Google Chrome before 4.0.249.89 populates an authentication dialog with credentials that were stored by Password Manager for a different web site, which allows user-a…
|
CWE-255
Credentials Management
|
CVE-2010-0556
|
2018-10-11 04:53 |
2010-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287554
|
- |
|
myshell
|
evalsmsi
|
SQL injection vulnerability in ajax.php in evalSMSI 2.1.03 allows remote attackers to execute arbitrary SQL commands via the query parameter in the (1) question action, and possibly the (2) sub_par o…
|
CWE-89
SQL Injection
|
CVE-2010-0614
|
2018-10-11 04:53 |
2010-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287555
|
- |
|
myshell
|
evalsmsi
|
Cross-site scripting (XSS) vulnerability in assess.php in evalSMSI 2.1.03 allows remote attackers to inject arbitrary web script or HTML via the reports comment box in a continue_assess action. NOTE…
|
CWE-79
Cross-site Scripting
|
CVE-2010-0615
|
2018-10-11 04:53 |
2010-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287556
|
- |
|
myshell
|
evalsmsi
|
evalSMSI 2.1.03 stores passwords in cleartext in the database, which allows attackers with database access to gain privileges. NOTE: remote attack vectors are possible by leveraging a separate SQL i…
|
CWE-255
Credentials Management
|
CVE-2010-0616
|
2018-10-11 04:53 |
2010-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287557
|
- |
|
lexmark
|
z2420
|
The flood-protection feature in the base, IPDS DLE, Forms DLE, Barcode DLE, Prescribe DLE, and Printcryption DLE components on certain Lexmark laser and inkjet printers and MarkNet devices allows rem…
|
NVD-CWE-Other
|
CVE-2010-0618
|
2018-10-11 04:53 |
2010-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287558
|
- |
|
lexmark
|
z2420
|
Per: http://support.lexmark.com/index?page=content&id=TE85&locale=EN&userlocale=EN_US#Printcryption
'Details
Lexmark products have connection flood protection mechanisms that limit the number o…
|
NVD-CWE-Other
|
CVE-2010-0618
|
2018-10-11 04:53 |
2010-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287559
|
- |
|
lexmark
|
x94x
|
Stack-based buffer overflow in the base, IPDS DLE, Forms DLE, Barcode DLE, Prescribe DLE, and Printcryption DLE components on certain Lexmark laser printers and multi-function printers allows remote …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-0619
|
2018-10-11 04:53 |
2010-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287560
|
- |
|
emc
|
homebase_server
|
Directory traversal vulnerability in the SSL Service in EMC HomeBase Server 6.2.x before 6.2.3 and 6.3.x before 6.3.2 allows remote attackers to overwrite arbitrary files with any content, and conseq…
|
CWE-22
Path Traversal
|
CVE-2010-0620
|
2018-10-11 04:53 |
2010-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|