|
250901
|
9.8 |
CRITICAL
Network
|
ultimate_php_board_project
|
ultimate_php_board
|
register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with a capital "A," but allows a remote attacker to impersonate the administrator by registering an account …
|
CWE-178
Improper Handling of Case Sensitivity
|
CVE-2002-1820
|
2024-02-16 06:19 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250902
|
- |
|
openpkg trustix hp avaya debian php
|
openpkg secure_linux hp-ux converged_communications_server debian_linux php
|
The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute arbitrary code by …
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2004-0594
|
2024-02-16 06:17 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250903
|
- |
|
php debian apple
|
php debian_linux mac_os_x
|
PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, which allows remote attackers to cause a denial of s…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2009-4017
|
2024-02-16 06:16 |
2009-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250904
|
- |
|
cisco
|
unified_communications_manager
|
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2a)su1, and 7.1 before 7.1(2a)su1 allows remote attackers to cause a d…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2009-2054
|
2024-02-16 06:15 |
2009-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250905
|
7.5 |
HIGH
Network
|
pldaniels
|
altermime
|
Off-by-one error in alterMIME 0.1.10 and 0.1.11 allows remote attackers to cause a denial of service (crash) via an x-header that causes snprintf overwrite the FFGET_FILE variable with a (null) byte.
|
CWE-193
Off-by-one Error
|
CVE-2002-1721
|
2024-02-16 06:13 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250906
|
7.0 |
HIGH
Local
|
linux novell opensuse suse canonical fedoraproject vmware redhat
|
linux_kernel linux_desktop opensuse suse_linux_enterprise_server suse_linux_enterprise_desktop ubuntu_linux fedora esx vma enterprise_linux_server enterprise_linux_deskt…
|
Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting…
|
CWE-362 CWE-476 CWE-672
Race Condition NULL Pointer Dereference Operation on a Resource after Expiration or Release
|
CVE-2009-3547
|
2024-02-16 06:12 |
2009-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250907
|
7.5 |
HIGH
Network
|
hadrons
|
xfstt
|
Off-by-one error in certain versions of xfstt allows remote attackers to read potentially sensitive memory via a malformed client request in the connection handshake, which leaks the memory in the se…
|
CWE-193
Off-by-one Error
|
CVE-2003-0625
|
2024-02-16 06:12 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250908
|
- |
|
tcpdump
|
tcpdump
|
Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payload with a length t…
|
CWE-125 CWE-191
Out-of-bounds Read Integer Underflow (Wrap or Wraparound)
|
CVE-2004-0184
|
2024-02-16 06:09 |
2004-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250909
|
- |
|
openbsd
|
openbsd
|
isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a delete payload containing a large number of SPIs, which triggers an out-of-…
|
CWE-125
Out-of-bounds Read
|
CVE-2004-0221
|
2024-02-16 06:09 |
2004-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250910
|
9.9 |
CRITICAL
Network
|
qemu redhat
|
qemu enterprise_linux_server enterprise_linux_workstation
|
Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earlier might allow guest OS users to execute arbitrary code on the host OS by establishing a connection from a V…
|
CWE-416
Use After Free
|
CVE-2009-3616
|
2024-02-16 06:06 |
2009-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|