|
298521
|
- |
|
mojolicious
|
mojolicious
|
Cross-site scripting (XSS) vulnerability in the link_to helper in Mojolicious before 1.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2011-1841
|
2024-11-21 10:27 |
2011-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298522
|
- |
|
ibm
|
rational_build_forge
|
IBM Rational Build Forge 7.1.0 uses the HTTP GET method during redirection from the authentication servlet to a PHP script, which makes it easier for context-dependent attackers to discover session I…
|
CWE-200
Information Exposure
|
CVE-2011-1839
|
2024-11-21 10:27 |
2011-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298523
|
- |
|
ibm
|
tivoli_directory_server
|
The LDAP_ADD implementation in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0009 stores a cleartext SHA password in the change log, which might allow local users to obtain sensitiv…
|
CWE-255
Credentials Management
|
CVE-2011-1822
|
2024-11-21 10:27 |
2011-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298524
|
- |
|
ibm
|
tivoli_directory_server
|
IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010 on Windows allows remote authenticated users to cause a denial of service (daemon hang) via a cn=changelog search.
|
CWE-399
Resource Management Errors
|
CVE-2011-1821
|
2024-11-21 10:27 |
2011-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298525
|
- |
|
ibm
|
tivoli_directory_server
|
IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009), 6.1 before 6.1.0.40 (aka 6.1.0.5-TIV-ITDS-IF0003), 6.2 before 6.2.0.16 (aka 6.…
|
CWE-200
Information Exposure
|
CVE-2011-1820
|
2024-11-21 10:27 |
2011-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298526
|
6.5 |
MEDIUM
Network
|
wordpress
|
wordpress
|
A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to pos…
|
CWE-276
Incorrect Default Permissions
|
CVE-2011-1762
|
2024-11-21 10:26 |
2022-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298527
|
6.1 |
MEDIUM
Network
|
rubyonrails
|
rails
|
A cross-site scripting vulnerability flaw was found in the auto_link function in Rails before version 3.0.6.
|
-
|
CVE-2011-1497
|
2024-11-21 10:26 |
2021-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298528
|
8.8 |
HIGH
Network
|
openvas
|
openvas_manager
|
OpenVAS Manager v2.0.3 allows plugin remote code execution.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2011-1597
|
2024-11-21 10:26 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298529
|
9.8 |
CRITICAL
Network
|
sap
|
netweaver
|
SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. By sending a specially-crafted packet, an attacker could exploit this vulnerabi…
|
NVD-CWE-noinfo
|
CVE-2011-1517
|
2024-11-21 10:26 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298530
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
A locally locally exploitable DOS vulnerability was found in pax-linux versions 2.6.32.33-test79.patch, 2.6.38-test3.patch, and 2.6.37.4-test14.patch. A bad bounds check in arch_get_unmapped_area_top…
|
CWE-400 CWE-835
Uncontrolled Resource Consumption Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2011-1474
|
2024-11-21 10:26 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|