|
303661
|
7.0 |
HIGH
Local
|
vmware
|
open-vm-tools
|
An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can bypass intended access restrictions on mounting shares via a symlink attack that leverages a realpath race condition in mou…
|
CWE-59
Link Following
|
CVE-2009-1143
|
2024-11-21 10:01 |
2022-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303662
|
6.7 |
MEDIUM
Local
|
vmware
|
open_vm_tools
|
An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can gain privileges via a symlink attack on /tmp files if vmware-user-suid-wrapper is setuid root and the ChmodChownDirectory f…
|
CWE-59
Link Following
|
CVE-2009-1142
|
2024-11-21 10:01 |
2022-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303663
|
9.8 |
CRITICAL
Network
|
apple
|
files
|
Multiple buffer overflows in the (1) cdf_read_sat, (2) cdf_read_long_sector_chain, and (3) cdf_read_ssat function in file before 5.02.
|
CWE-120
Classic Buffer Overflow
|
CVE-2009-0948
|
2024-11-21 10:01 |
2021-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303664
|
9.8 |
CRITICAL
Network
|
apple
|
files
|
Multiple integer overflows in the (1) cdf_read_property_info and (2) cdf_read_sat functions in file before 5.02.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2009-0947
|
2024-11-21 10:01 |
2021-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303665
|
9.8 |
CRITICAL
Network
|
dell
|
emc_replistor
|
EMC RepliStor Server Service before ESA-09-003 has a DoASOCommand Remote Code Execution Vulnerability. The flaw exists within the DoRcvRpcCall RPC function -exposed via the rep_srv.exe process- where…
|
NVD-CWE-noinfo
|
CVE-2009-1120
|
2024-11-21 10:01 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303666
|
6.1 |
MEDIUM
Network
|
apache
|
juddi
|
Cross-site scripting (XSS) vulnerability in Apache jUDDI before 2.0 allows remote attackers to inject arbitrary web script or HTML via the dsname parameter to happyjuddi.jsp.
|
CWE-79
Cross-site Scripting
|
CVE-2009-1198
|
2024-11-21 10:01 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303667
|
5.3 |
MEDIUM
Network
|
apache
|
juddi
|
Apache jUDDI before 2.0 allows attackers to spoof entries in log files via vectors related to error logging of keys from uddiget.jsp.
|
CWE-20
Improper Input Validation
|
CVE-2009-1197
|
2024-11-21 10:01 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303668
|
- |
|
ibm
|
websphere_mq
|
IBM WebSphere MQ 6.0 before 6.0.2.8 and 7.0 before 7.0.1.0 does not properly handle long group names, which might allow local users to gain privileges by leveraging combinations of group names with t…
|
CWE-20
Improper Input Validation
|
CVE-2009-0905
|
2024-11-21 10:01 |
2011-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303669
|
- |
|
ibm
|
websphere_mq
|
Heap-based buffer overflow in the client in IBM WebSphere MQ 6.0 before 6.0.2.7 and 7.0 before 7.0.1.0 allows local users to gain privileges via crafted SSL information in a Client Channel Definition…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-0900
|
2024-11-21 10:01 |
2011-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303670
|
- |
|
dell
|
wyse_device_manager
|
hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain management access via a crafted query, as demonstrated by a V52 que…
|
CWE-287
Improper Authentication
|
CVE-2009-0695
|
2024-11-21 10:00 |
2012-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|