|
299641
|
- |
|
network-13
|
n-13_news
|
Cross-site request forgery (CSRF) vulnerability in news/admin.php in N-13 News 3.4, 3.7, and 4.0 allows remote attackers to hijack the authentication of administrators for requests that create new us…
|
CWE-352
Origin Validation Error
|
CVE-2011-0642
|
2024-11-21 10:24 |
2011-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299642
|
- |
|
heart5
|
statpresscn
|
Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/admin.php in the StatPressCN plugin 1.9.0 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) what1…
|
CWE-79
Cross-site Scripting
|
CVE-2011-0641
|
2024-11-21 10:24 |
2011-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299643
|
- |
|
udev_project
|
udev
|
The default configuration of udev on Linux does not warn the user before enabling additional Human Interface Device (HID) functionality over USB, which allows user-assisted attackers to execute arbit…
|
NVD-CWE-noinfo
|
CVE-2011-0640
|
2024-11-21 10:24 |
2011-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299644
|
- |
|
apple
|
mac_os_x
|
Apple Mac OS X does not properly warn the user before enabling additional Human Interface Device (HID) functionality over USB, which allows user-assisted attackers to execute arbitrary programs via c…
|
CWE-16
Configuration
|
CVE-2011-0639
|
2024-11-21 10:24 |
2011-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299645
|
- |
|
microsoft
|
windows
|
Microsoft Windows does not properly warn the user before enabling additional Human Interface Device (HID) functionality over USB, which allows user-assisted attackers to execute arbitrary programs vi…
|
CWE-16
Configuration
|
CVE-2011-0638
|
2024-11-21 10:24 |
2011-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299646
|
- |
|
ibm
|
aix
|
The FC SCSI protocol driver in IBM AIX 6.1 does not verify that a timer is unused before deallocating this timer, which might allow attackers to cause a denial of service (system crash) via unspecifi…
|
NVD-CWE-noinfo
|
CVE-2011-0637
|
2024-11-21 10:24 |
2011-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299647
|
- |
|
nvidia
|
cuda_toolkit
|
The (1) cudaHostAlloc and (2) cuMemHostAlloc functions in the NVIDIA CUDA Toolkit 3.2 developer drivers for Linux 260.19.26, and possibly other versions, do not initialize pinned memory, which allows…
|
CWE-200
Information Exposure
|
CVE-2011-0636
|
2024-11-21 10:24 |
2011-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299648
|
- |
|
simploo
|
simploo_cms
|
Static code injection vulnerability in Simploo CMS 1.7.1 and earlier allows remote authenticated users to inject arbitrary PHP code into config/custom/base.ini.php via the ftpserver parameter (FTP-Se…
|
CWE-94
Code Injection
|
CVE-2011-0635
|
2024-11-21 10:24 |
2011-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299649
|
- |
|
gallarific
|
php_photo_gallery_script
|
SQL injection vulnerability in gallery.php in Gallarific PHP Photo Gallery script 2.1 and possibly other versions allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2011-0519
|
2024-11-21 10:24 |
2011-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299650
|
- |
|
lotuscms
|
fraise
|
Directory traversal vulnerability in core/lib/router.php in LotusCMS Fraise 3.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via the system…
|
CWE-22
Path Traversal
|
CVE-2011-0518
|
2024-11-21 10:24 |
2011-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|