|
278151
|
- |
|
sun
|
java_se jdk jre sdk
|
Unspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for Business, in JDK and JRE 6 Update 14 and earlier and JDK and JRE 5.0 Update 19 and earlier; and Java SE for Business in SDK …
|
NVD-CWE-noinfo
|
CVE-2009-2676
|
2018-10-31 01:26 |
2009-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278152
|
- |
|
opera
|
opera_browser
|
Opera 9.52 and earlier, and 10.00 Beta 3 Build 1699, does not properly block data: URIs in Location headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) atta…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3013
|
2018-10-31 01:26 |
2009-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278153
|
- |
|
opera
|
opera_browser
|
Opera before 10.00 trusts root X.509 certificates signed with the MD2 algorithm, which makes it easier for man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted server certificate.
|
CWE-310
Cryptographic Issues
|
CVE-2009-3045
|
2018-10-31 01:26 |
2009-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278154
|
- |
|
opera
|
opera_browser
|
Opera before 10.00, when a collapsed address bar is used, does not properly update the domain name from the previously visited site to the currently visited site, which might allow remote attackers t…
|
NVD-CWE-Other
|
CVE-2009-3047
|
2018-10-31 01:26 |
2009-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278155
|
- |
|
opera
|
opera_browser
|
Opera before 10.00 does not properly display all characters in Internationalized Domain Names (IDN) in the address bar, which allows remote attackers to spoof URLs and conduct phishing attacks, relat…
|
NVD-CWE-Other
|
CVE-2009-3049
|
2018-10-31 01:26 |
2009-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278156
|
- |
|
opera
|
opera_browser
|
Opera before 10.01 does not properly restrict HTML in a (1) RSS or (2) Atom feed, which allows remote attackers to conduct cross-site scripting (XSS) attacks, and conduct cross-zone scripting attacks…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3266
|
2018-10-31 01:26 |
2009-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278157
|
- |
|
php
|
php
|
The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability t…
|
CWE-20
Improper Input Validation
|
CVE-2009-3291
|
2018-10-31 01:26 |
2009-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278158
|
- |
|
php
|
php
|
Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."
|
NVD-CWE-noinfo
|
CVE-2009-3292
|
2018-10-31 01:26 |
2009-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278159
|
- |
|
php
|
php
|
Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."
|
NVD-CWE-noinfo
|
CVE-2009-3293
|
2018-10-31 01:26 |
2009-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278160
|
- |
|
php
|
php
|
The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass safe_mode restrictions, and create files in group-writable or worl…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-3557
|
2018-10-31 01:26 |
2009-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|