|
298041
|
- |
|
nazgul
|
nostromo
|
Directory traversal vulnerability in nhttpd (aka Nostromo webserver) before 1.9.4 allows remote attackers to execute arbitrary programs or read arbitrary files via a ..%2f (encoded dot dot slash) in …
|
CWE-22
Path Traversal
|
CVE-2011-0751
|
2024-11-21 10:24 |
2011-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298042
|
- |
|
sugarcrm
|
sugarcrm
|
SugarCRM before 6.1.3 does not properly handle reloads and direct requests for a warning page produced by a certain duplicate check, which allows remote authenticated users to discover (1) the names …
|
CWE-20
Improper Input Validation
|
CVE-2011-0745
|
2024-11-21 10:24 |
2011-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298043
|
- |
|
emc
|
avamar
|
Unspecified vulnerability in EMC Avamar before 5.0.4-30 allows remote authenticated users to gain privileges via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2011-0648
|
2024-11-21 10:24 |
2011-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298044
|
- |
|
linux redhat canonical
|
linux_kernel enterprise_linux_server enterprise_linux_workstation enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_eus ubuntu_linux
|
Race condition in the cm_work_handler function in the InfiniBand driver (drivers/infiniband/core/cma.c) in Linux kernel 2.6.x allows remote attackers to cause a denial of service (panic) by sending a…
|
CWE-362
Race Condition
|
CVE-2011-0695
|
2024-11-21 10:24 |
2011-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298045
|
- |
|
e107
|
e107
|
Cross-site scripting (XSS) vulnerability in e107 0.7.22 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2011-0457
|
2024-11-21 10:24 |
2011-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298046
|
- |
|
wordpress
|
wordpress
|
wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter.
|
CWE-200
Information Exposure
|
CVE-2011-0701
|
2024-11-21 10:24 |
2011-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298047
|
- |
|
wordpress
|
wordpress
|
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit ti…
|
CWE-79
Cross-site Scripting
|
CVE-2011-0700
|
2024-11-21 10:24 |
2011-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298048
|
- |
|
apache
|
subversion
|
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) …
|
NVD-CWE-Other
|
CVE-2011-0715
|
2024-11-21 10:24 |
2011-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298049
|
- |
|
otrs
|
otrs
|
webscript.pl in Open Ticket Request System (OTRS) 2.3.4 and earlier allows remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injection vulnerability."
|
CWE-78
OS Command
|
CVE-2011-0456
|
2024-11-21 10:24 |
2011-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298050
|
- |
|
novell
|
vibe_onprem
|
Unspecified vulnerability in Novell Vibe OnPrem 3.0 before Hot Patch 1 allows remote attackers to execute arbitrary code via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2011-0464
|
2024-11-21 10:24 |
2011-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|