|
287621
|
- |
|
toutvirtual
|
virtualiq
|
Multiple cross-site request forgery (CSRF) vulnerabilities in ToutVirtual VirtualIQ Pro 3.2 build 7882 and 3.5 build 8691 allow remote attackers to hijack the authentication of administrators for req…
|
CWE-352
Origin Validation Error
|
CVE-2009-4849
|
2018-10-11 04:49 |
2010-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287622
|
- |
|
bernhard_frohlich
|
phpcom
|
Multiple SQL injection vulnerabilities in phpCommunity 2 2.1.8, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the forum_id parameter in a forum a…
|
CWE-89
SQL Injection
|
CVE-2009-4884
|
2018-10-11 04:49 |
2010-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287623
|
- |
|
bernhard_frohlich
|
phpcom
|
Cross-site scripting (XSS) vulnerability in templates/1/login.php in phpCommunity 2 2.1.8 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4885
|
2018-10-11 04:49 |
2010-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287624
|
- |
|
bernhard_frohlich
|
phpcom
|
Multiple directory traversal vulnerabilities in phpCommunity 2 2.1.8 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter to module/admin/files/show_file.php an…
|
CWE-22
Path Traversal
|
CVE-2009-4886
|
2018-10-11 04:49 |
2010-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287625
|
- |
|
retrieve
|
vbook
|
Multiple cross-site scripting (XSS) vulnerabilities in the login application in vBook 4.2.17 allow remote attackers to inject arbitrary web script or HTML via the (1) title and (2) message parameters.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4890
|
2018-10-11 04:49 |
2010-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287626
|
- |
|
adobe
|
shockwave_player
|
Heap-based buffer overflow in Adobe Shockwave Player before 11.5.6.606 allows remote attackers to execute arbitrary code via a crafted 3D model in a Shockwave file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-4002
|
2018-10-11 04:48 |
2010-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287627
|
- |
|
adobe
|
shockwave_player
|
Multiple integer overflows in Adobe Shockwave Player before 11.5.6.606 allow remote attackers to execute arbitrary code via (1) an unspecified block type in a Shockwave file, leading to a heap-based …
|
CWE-189
Numeric Errors
|
CVE-2009-4003
|
2018-10-11 04:48 |
2010-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287628
|
- |
|
powerdns
|
recursor
|
Buffer overflow in PowerDNS Recursor before 3.1.7.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted packets.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-4009
|
2018-10-11 04:48 |
2010-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287629
|
- |
|
powerdns
|
recursor
|
Unspecified vulnerability in PowerDNS Recursor before 3.1.7.2 allows remote attackers to spoof DNS data via crafted zones.
|
NVD-CWE-noinfo
|
CVE-2009-4010
|
2018-10-11 04:48 |
2010-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287630
|
- |
|
gnu
|
automake
|
The (1) dist or (2) distcheck rules in GNU Automake 1.11.1, 1.10.3, and release branches branch-1-4 through branch-1-9, when producing a distribution tarball for a package that uses Automake, assign …
|
CWE-362
Race Condition
|
CVE-2009-4029
|
2018-10-11 04:48 |
2009-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|