|
300101
|
- |
|
python
|
python
|
The urllib and urllib2 modules in Python 2.x before 2.7.2 and 3.x before 3.2.1 process Location headers that specify redirection to file: URLs, which makes it easier for remote attackers to obtain se…
|
CWE-399
Resource Management Errors
|
CVE-2011-1521
|
2024-11-21 10:26 |
2011-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300102
|
- |
|
emc
|
sourceone_email_management
|
The default configuration of ExShortcut\Web.config in EMC SourceOne Email Management before 6.6 SP1, when the Mobile Services component is used, does not properly set the localOnly attribute of the t…
|
CWE-16
Configuration
|
CVE-2011-1424
|
2024-11-21 10:26 |
2011-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300103
|
- |
|
radvision
|
iview_suite
|
SQL injection vulnerability in RADVISION iVIEW Suite before 7.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2011-1328
|
2024-11-21 10:26 |
2011-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300104
|
- |
|
pureftpd
|
pure-ftpd
|
The STARTTLS implementation in ftp_parser.c in Pure-FTPd before 1.0.30 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted FTP session…
|
CWE-399
Resource Management Errors
|
CVE-2011-1575
|
2024-11-21 10:26 |
2011-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300105
|
- |
|
apache
|
tomcat
|
Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-1582
|
2024-11-21 10:26 |
2011-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300106
|
- |
|
trendmicro
|
trend_micro_internet_security
|
The Keystroke Encryption feature in Trend Micro Internet Security 2009 (aka Virus Buster 2009 and PC-cillin 2009) does not completely encrypt passwords, which allows local users to obtain sensitive i…
|
CWE-310
Cryptographic Issues
|
CVE-2011-1327
|
2024-11-21 10:26 |
2011-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300107
|
- |
|
exim
|
exim
|
The DKIM implementation in Exim 4.7x before 4.76 permits matching for DKIM identities to apply to lookup items, instead of only strings, which allows remote attackers to execute arbitrary code or acc…
|
CWE-20
Improper Input Validation
|
CVE-2011-1407
|
2024-11-21 10:26 |
2011-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300108
|
- |
|
mahara
|
mahara
|
Mahara before 1.3.6 does not properly handle an https URL in the wwwroot configuration setting, which makes it easier for user-assisted remote attackers to obtain credentials by sniffing the network …
|
CWE-16
Configuration
|
CVE-2011-1406
|
2024-11-21 10:26 |
2011-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300109
|
- |
|
mahara
|
mahara
|
Cross-site scripting (XSS) vulnerability in Mahara before 1.3.6 allows remote authenticated users to inject arbitrary web script or HTML via vectors associated with HTML e-mail messages, related to a…
|
CWE-79
Cross-site Scripting
|
CVE-2011-1405
|
2024-11-21 10:26 |
2011-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300110
|
- |
|
mahara
|
mahara
|
Mahara before 1.3.6 does not properly restrict the data in responses to AJAX calls, which allows remote authenticated users to obtain sensitive information via a request associated with (1) blocktype…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-1404
|
2024-11-21 10:26 |
2011-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|