|
303101
|
- |
|
juniper
|
idp
|
Cross-site scripting (XSS) vulnerability in Appliance Configuration Manager (ACM) in Juniper IDP 4.1 before 4.1r3 and 4.2 before 4.2r1 allows remote attackers to inject arbitrary web script or HTML v…
|
CWE-79
Cross-site Scripting
|
CVE-2009-5086
|
2024-11-21 10:11 |
2011-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303102
|
- |
|
libpng
|
libpng
|
Memory leak in the embedded_profile_len function in pngwutil.c in libpng before 1.2.39beta5 allows context-dependent attackers to cause a denial of service (memory leak or segmentation fault) via a J…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2009-5063
|
2024-11-21 10:11 |
2011-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303103
|
- |
|
ibm
|
tivoli_federated_identity_manager
|
IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when configured as an OpenID provider, does not delete the site information cookie in response to a user's deletion of a relying-par…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-5085
|
2024-11-21 10:11 |
2011-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303104
|
- |
|
ibm
|
tivoli_federated_identity_manager
|
IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when com.tivoli.am.fim.infocard.delegates.InfoCardSTSDelegate tracing is enabled, creates a cleartext log entry containing a passwor…
|
CWE-310
Cryptographic Issues
|
CVE-2009-5084
|
2024-11-21 10:11 |
2011-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303105
|
- |
|
ibm
|
tivoli_federated_identity_manager
|
IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when configured as an OpenID relying party, does not perform the expected login rejection upon receiving an OP-Identifier from an Op…
|
CWE-287
Improper Authentication
|
CVE-2009-5083
|
2024-11-21 10:11 |
2011-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303106
|
- |
|
gnu
|
groff
|
The (1) configure and (2) config.guess scripts in GNU troff (aka groff) 1.20.1 on Openwall GNU/*/Linux (aka Owl) improperly create temporary files upon a failure of the mktemp function, which makes i…
|
CWE-59
Link Following
|
CVE-2009-5082
|
2024-11-21 10:11 |
2011-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303107
|
- |
|
gnu
|
groff
|
The (1) config.guess, (2) contrib/groffer/perl/groffer.pl, and (3) contrib/groffer/perl/roff2.pl scripts in GNU troff (aka groff) 1.21 and earlier use an insufficient number of X characters in the te…
|
CWE-59
Link Following
|
CVE-2009-5081
|
2024-11-21 10:11 |
2011-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303108
|
- |
|
gnu
|
groff
|
The (1) contrib/eqn2graph/eqn2graph.sh, (2) contrib/grap2graph/grap2graph.sh, and (3) contrib/pic2graph/pic2graph.sh scripts in GNU troff (aka groff) 1.21 and earlier do not properly handle certain f…
|
CWE-59
Link Following
|
CVE-2009-5080
|
2024-11-21 10:11 |
2011-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303109
|
- |
|
gnu
|
groff
|
The (1) gendef.sh, (2) doc/fixinfo.sh, and (3) contrib/gdiffmk/tests/runtests.in scripts in GNU troff (aka groff) 1.21 and earlier allow local users to overwrite arbitrary files via a symlink attack …
|
CWE-59
Link Following
|
CVE-2009-5079
|
2024-11-21 10:11 |
2011-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303110
|
6.5 |
MEDIUM
Network
|
gnu apple
|
groff mac_os_x
|
contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER option, which allows remote attackers to create, overwrite, rename, or delete arbi…
|
CWE-254
7PK - Security Features
|
CVE-2009-5078
|
2024-11-21 10:11 |
2011-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|