|
303671
|
- |
|
dell
|
wyse_device_manager
|
Multiple buffer overflows in Wyse Device Manager (WDM) 4.7.x allow remote attackers to execute arbitrary code via (1) the User-Agent HTTP header to hserver.dll or (2) unspecified input to hagent.exe.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-0693
|
2024-11-21 10:00 |
2012-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303672
|
- |
|
redhat
|
network_satellite_server
|
Red Hat Network (RHN) Satellite Server 5.3 and 5.4 does not properly rewrite unspecified URLs, which allows remote attackers to (1) obtain unspecified sensitive host information or (2) use the server…
|
CWE-200
Information Exposure
|
CVE-2009-0788
|
2024-11-21 10:00 |
2011-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303673
|
7.5 |
HIGH
Network
|
mirc
|
mirc
|
mIRC before 6.35 allows attackers to cause a denial of service (crash) via a long nickname.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2008-7314
|
2024-11-21 09:58 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303674
|
7.8 |
HIGH
Local
|
getfiregpg
|
iceweasel-firegpg
|
A symlink issue exists in Iceweasel-firegpg before 0.6 due to insecure tempfile handling.
|
CWE-59
Link Following
|
CVE-2008-7273
|
2024-11-21 09:58 |
2019-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303675
|
5.5 |
MEDIUM
Local
|
alsa-project
|
alsa
|
alsa-utils 1.0.19 and later versions allows local users to overwrite arbitrary files via a symlink attack via the /usr/bin/alsa-info and /usr/bin/alsa-info.sh scripts.
|
CWE-59
Link Following
|
CVE-2009-0035
|
2024-11-21 09:58 |
2019-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303676
|
9.8 |
CRITICAL
Network
|
gri_project debian
|
gri debian_linux
|
gri before 2.12.18 generates temporary files in an insecure way.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2008-7291
|
2024-11-21 09:58 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303677
|
7.5 |
HIGH
Network
|
getfiregpg
|
firegpg
|
FireGPG before 0.6 handle user’s passphrase and decrypted cleartext insecurely by writing pre-encrypted cleartext and the user's passphrase to disk which may result in the compromise of secure commun…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2008-7272
|
2024-11-21 09:58 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303678
|
6.1 |
MEDIUM
Network
|
tubepress
|
tubepress
|
The tubepress plugin before 1.6.5 for WordPress has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2008-7321
|
2024-11-21 09:58 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303679
|
6.8 |
MEDIUM
Physics
|
gnome
|
seahorse
|
GNOME Seahorse through 3.30 allows physically proximate attackers to read plaintext passwords by using the quickAllow dialog at an unattended workstation, if the keyring is unlocked. NOTE: this is di…
|
CWE-255
Credentials Management
|
CVE-2008-7320
|
2024-11-21 09:58 |
2018-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303680
|
9.8 |
CRITICAL
Network
|
net-ping-external_project
|
net-ping-external
|
The Net::Ping::External extension through 0.15 for Perl does not properly sanitize arguments (e.g., invalid hostnames) containing shell metacharacters before use of backticks in External.pm, allowing…
|
CWE-77
Command Injection
|
CVE-2008-7319
|
2024-11-21 09:58 |
2017-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|