|
287541
|
- |
|
becauseinter
|
bournal
|
Bournal before 1.4.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified temporary files associated with a --hack_the_gibson update check.
|
CWE-59
Link Following
|
CVE-2010-0118
|
2018-10-11 04:51 |
2010-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287542
|
- |
|
becauseinter
|
bournal
|
Bournal before 1.4.1 on FreeBSD 8.0, when the -K option is used, places a ccrypt key on the command line, which allows local users to obtain sensitive information by listing the process and its argum…
|
CWE-200
Information Exposure
|
CVE-2010-0119
|
2018-10-11 04:51 |
2010-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287543
|
- |
|
timeclock-software
|
employee_timeclock_software
|
Multiple SQL injection vulnerabilities in Employee Timeclock Software 0.99 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to (a) auth.php or (…
|
CWE-89
SQL Injection
|
CVE-2010-0122
|
2018-10-11 04:51 |
2010-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287544
|
- |
|
timeclock-software
|
employee_timeclock_software
|
The database backup implementation in Employee Timeclock Software 0.99 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a da…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-0123
|
2018-10-11 04:51 |
2010-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287545
|
- |
|
timeclock-software
|
employee_timeclock_software
|
Employee Timeclock Software 0.99 places the database password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.
|
CWE-255
Credentials Management
|
CVE-2010-0124
|
2018-10-11 04:51 |
2010-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287546
|
- |
|
viewvc
|
viewvc
|
Cross-site scripting (XSS) vulnerability in ViewVC 1.1 before 1.1.5 and 1.0 before 1.0.11, when the regular expression search functionality is enabled, allows remote attackers to inject arbitrary web…
|
CWE-79
Cross-site Scripting
|
CVE-2010-0132
|
2018-10-11 04:51 |
2010-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287547
|
- |
|
mozilla
|
firefox seamonkey
|
The Web Worker functionality in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly handle array data types for posted messages, which allows rem…
|
CWE-399
Resource Management Errors
|
CVE-2010-0160
|
2018-10-11 04:51 |
2010-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287548
|
- |
|
mozilla
|
firefox
|
Use-after-free vulnerability in the imgContainer::InternalAddFrameHelper function in src/imgContainer.cpp in libpr0n in Mozilla Firefox 3.6 before 3.6.2 allows remote attackers to cause a denial of s…
|
CWE-399
Resource Management Errors
|
CVE-2010-0164
|
2018-10-11 04:51 |
2010-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287549
|
- |
|
microsoft
|
windows_live_messenger
|
A certain ActiveX control in msgsc.14.0.8089.726.dll in Microsoft Windows Live Messenger 2009 build 14.0.8089.726 on Windows Vista and Windows 7 allows remote attackers to cause a denial of service (…
|
NVD-CWE-Other
|
CVE-2010-0278
|
2018-10-11 04:51 |
2010-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287550
|
- |
|
jan_eric_krprianidis google
|
lib3ds google_sketchup
|
Array index error in Jan Eric Kyprianidis lib3ds 1.x, as used in Google SketchUp 7.x before 7.1 M2, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitr…
|
CWE-189
Numeric Errors
|
CVE-2010-0280
|
2018-10-11 04:51 |
2010-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|