|
287481
|
- |
|
geopp
|
geo\+\+_gncaster
|
HTTP authentication implementation in Geo++ GNCASTER 1.4.0.7 and earlier allows remote attackers to read authentication headers of other users via a large request with an incorrect authentication att…
|
CWE-200
Information Exposure
|
CVE-2010-0551
|
2018-10-11 04:53 |
2010-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287482
|
- |
|
geopp
|
geo\+\+_gncaster
|
Geo++ GNCASTER 1.4.0.7 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via multiple requests for a non-existent file using a l…
|
CWE-20
Improper Input Validation
|
CVE-2010-0552
|
2018-10-11 04:53 |
2010-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287483
|
- |
|
geopp
|
geo\+\+_gncaster
|
Geo++ GNCASTER 1.4.0.7 and earlier allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a long NMEA data sentence.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-0553
|
2018-10-11 04:53 |
2010-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287484
|
- |
|
geopp
|
geo\+\+_gncaster
|
The HTTP Authentication implementation in Geo++ GNCASTER 1.4.0.7 and earlier uses the same nonce for all authentication, which allows remote attackers to hijack web sessions or bypass authentication …
|
CWE-287
Improper Authentication
|
CVE-2010-0554
|
2018-10-11 04:53 |
2010-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287485
|
- |
|
google
|
chrome
|
browser/login/login_prompt.cc in Google Chrome before 4.0.249.89 populates an authentication dialog with credentials that were stored by Password Manager for a different web site, which allows user-a…
|
CWE-255
Credentials Management
|
CVE-2010-0556
|
2018-10-11 04:53 |
2010-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287486
|
- |
|
myshell
|
evalsmsi
|
SQL injection vulnerability in ajax.php in evalSMSI 2.1.03 allows remote attackers to execute arbitrary SQL commands via the query parameter in the (1) question action, and possibly the (2) sub_par o…
|
CWE-89
SQL Injection
|
CVE-2010-0614
|
2018-10-11 04:53 |
2010-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287487
|
- |
|
myshell
|
evalsmsi
|
Cross-site scripting (XSS) vulnerability in assess.php in evalSMSI 2.1.03 allows remote attackers to inject arbitrary web script or HTML via the reports comment box in a continue_assess action. NOTE…
|
CWE-79
Cross-site Scripting
|
CVE-2010-0615
|
2018-10-11 04:53 |
2010-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287488
|
- |
|
myshell
|
evalsmsi
|
evalSMSI 2.1.03 stores passwords in cleartext in the database, which allows attackers with database access to gain privileges. NOTE: remote attack vectors are possible by leveraging a separate SQL i…
|
CWE-255
Credentials Management
|
CVE-2010-0616
|
2018-10-11 04:53 |
2010-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287489
|
- |
|
lexmark
|
z2420
|
The flood-protection feature in the base, IPDS DLE, Forms DLE, Barcode DLE, Prescribe DLE, and Printcryption DLE components on certain Lexmark laser and inkjet printers and MarkNet devices allows rem…
|
NVD-CWE-Other
|
CVE-2010-0618
|
2018-10-11 04:53 |
2010-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287490
|
- |
|
lexmark
|
z2420
|
Per: http://support.lexmark.com/index?page=content&id=TE85&locale=EN&userlocale=EN_US#Printcryption
'Details
Lexmark products have connection flood protection mechanisms that limit the number o…
|
NVD-CWE-Other
|
CVE-2010-0618
|
2018-10-11 04:53 |
2010-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|