|
303521
|
- |
|
ibm
|
filenet_p8_application_engine
|
The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x before 4.0.2.1-P8AE-FP001 does not record Get Content Failure Audit events, which might allow remote attackers to …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-5002
|
2024-11-21 10:10 |
2010-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303522
|
- |
|
ibm
|
filenet_p8_application_engine
|
The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x before 4.0.2.2-P8AE-FP002 grants a document's Creator-Owner full control over an annotation object, even if the de…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-5001
|
2024-11-21 10:10 |
2010-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303523
|
- |
|
ibm
|
filenet_p8_application_engine
|
Multiple cross-site scripting (XSS) vulnerabilities in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x before 4.0.2.3-P8AE-FP003 allow remote attackers to inject …
|
CWE-79
Cross-site Scripting
|
CVE-2009-5000
|
2024-11-21 10:10 |
2010-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303524
|
- |
|
ibm
|
filenet_p8_application_engine
|
Cross-site scripting (XSS) vulnerability in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-016 allows remote attackers to inject arbitrary web script …
|
CWE-79
Cross-site Scripting
|
CVE-2009-4999
|
2024-11-21 10:10 |
2010-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303525
|
- |
|
ibm
|
filenet_p8_application_engine
|
The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-019 and 4.0.2.x before 4.0.2.7-P8AE-FP007, in certain FileTracker configurations, does not apply a secu…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-4998
|
2024-11-21 10:10 |
2010-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303526
|
4.7 |
MEDIUM
Local
|
linux debian canonical
|
linux_kernel debian_linux ubuntu_linux
|
Race condition in the tty_fasync function in drivers/char/tty_io.c in the Linux kernel before 2.6.32.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or p…
|
CWE-362 CWE-476
Race Condition NULL Pointer Dereference
|
CVE-2009-4895
|
2024-11-21 10:10 |
2010-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303527
|
- |
|
gnome
|
power_manager
|
gnome-power-manager 2.27.92 does not properly implement the lock_on_suspend and lock_on_hibernate settings for locking the screen when the suspend or hibernate button is pressed, which might make it …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-4997
|
2024-11-21 10:10 |
2010-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303528
|
- |
|
xfce
|
xfce
|
Xfce4-session 4.5.91 in Xfce does not lock the screen when the suspend or hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-4996
|
2024-11-21 10:10 |
2010-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303529
|
- |
|
twiki
|
twiki
|
Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.2 allows remote attackers to hijack the authentication of arbitrary users for requests that update pages, as demonstrated by a URL …
|
CWE-352
Origin Validation Error
|
CVE-2009-4898
|
2024-11-21 10:10 |
2010-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303530
|
- |
|
smartertools
|
smartertrack
|
Cross-site scripting (XSS) vulnerability in frmTickets.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to inject arbitrary web script or HTML via the email address field. N…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4995
|
2024-11-21 10:10 |
2010-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|