|
298481
|
- |
|
imgburn
|
imgburn
|
Untrusted search path vulnerability in ImgBurn.exe in ImgBurn 2.4.0.0, 2.5.4.0, and other versions allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacki…
|
NVD-CWE-Other
|
CVE-2011-0403
|
2024-11-21 10:23 |
2011-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298482
|
- |
|
debian
|
dpkg
|
dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via a symlink attack on unspecified files in the .pc directory.
|
CWE-59
Link Following
|
CVE-2011-0402
|
2024-11-21 10:23 |
2011-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298483
|
- |
|
troglobit
|
pimd
|
pimd 2.1.5 and possibly earlier versions allows user-assisted local users to overwrite arbitrary files via a symlink attack on (1) pimd.dump when a USR1 signal is sent, or (2) pimd.cache when USR2 is…
|
CWE-59
Link Following
|
CVE-2011-0007
|
2024-11-21 10:23 |
2011-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298484
|
- |
|
joomla
|
com_search
|
Cross-site scripting (XSS) vulnerability in the com_search module for Joomla! 1.0.x through 1.0.15 allows remote attackers to inject arbitrary web script or HTML via the ordering parameter to index.p…
|
CWE-79
Cross-site Scripting
|
CVE-2011-0005
|
2024-11-21 10:23 |
2011-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298485
|
- |
|
mediawiki
|
mediawiki
|
MediaWiki before 1.16.1, when user or site JavaScript or CSS is enabled, allows remote attackers to conduct clickjacking attacks via unspecified vectors.
|
CWE-20
Improper Input Validation
|
CVE-2011-0003
|
2024-11-21 10:23 |
2011-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298486
|
- |
|
matomo
|
matomo
|
Piwik before 1.1 does not properly limit the number of files stored under tmp/sessions/, which might allow remote attackers to cause a denial of service (inode consumption) by establishing many sessi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-0401
|
2024-11-21 10:23 |
2011-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298487
|
- |
|
matomo
|
matomo
|
Cookie.php in Piwik before 1.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmiss…
|
CWE-16
Configuration
|
CVE-2011-0400
|
2024-11-21 10:23 |
2011-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298488
|
- |
|
matomo
|
matomo
|
Piwik before 1.1 does not prevent the rendering of the login form inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a craft…
|
NVD-CWE-Other
|
CVE-2011-0399
|
2024-11-21 10:23 |
2011-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298489
|
- |
|
matomo
|
matomo
|
The Piwik_Common::getIP function in Piwik before 1.1 does not properly determine the client IP address, which allows remote attackers to bypass intended geolocation and logging functionality via (1) …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-0398
|
2024-11-21 10:23 |
2011-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298490
|
- |
|
matomo
|
matomo
|
Multiple cross-site scripting (XSS) vulnerabilities in Piwik before 1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2011-0004
|
2024-11-21 10:23 |
2011-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|