|
304691
|
7.5 |
HIGH
Network
|
shibboleth debian
|
service_provider debian_linux
|
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default…
|
CWE-200 CWE-916
Information Exposure Use of Password Hash With Insufficient Computational Effort
|
CVE-2010-2450
|
2024-11-21 10:16 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304692
|
6.5 |
MEDIUM
Network
|
gource
|
gource
|
Gource through 0.26 logs to a predictable file name (/tmp/gource-$UID.tmp), enabling attackers to overwrite an arbitrary file via a symlink attack.
|
CWE-20
Improper Input Validation
|
CVE-2010-2449
|
2024-11-21 10:16 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304693
|
9.8 |
CRITICAL
Network
|
gitolite
|
gitolite
|
gitolite before 1.4.1 does not filter src/ or hooks/ from path names.
|
CWE-20
Improper Input Validation
|
CVE-2010-2447
|
2024-11-21 10:16 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304694
|
6.5 |
MEDIUM
Network
|
drupal
|
drupal
|
Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal s…
|
CWE-20
Improper Input Validation
|
CVE-2010-2473
|
2024-11-21 10:16 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304695
|
4.8 |
MEDIUM
Network
|
drupal
|
drupal
|
Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which c…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2472
|
2024-11-21 10:16 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304696
|
6.1 |
MEDIUM
Network
|
drupal
|
drupal
|
Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.
|
CWE-79
Cross-site Scripting
|
CVE-2010-2250
|
2024-11-21 10:16 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304697
|
7.5 |
HIGH
Network
|
linux
|
linux_kernel
|
A vulnerability exists in kernel/time/clocksource.c in the Linux kernel before 2.6.34 where on non-GENERIC_TIME systems (GENERIC_TIME=n), accessing /sys/devices/system/clocksource/clocksource0/curren…
|
CWE-20
Improper Input Validation
|
CVE-2010-2243
|
2024-11-21 10:16 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304698
|
6.1 |
MEDIUM
Network
|
drupal debian
|
drupal debian_linux
|
Drupal versions 5.x and 6.x has open redirection
|
CWE-601
Open Redirect
|
CVE-2010-2471
|
2024-11-21 10:16 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304699
|
9.8 |
CRITICAL
Network
|
ruby-rbot
|
rbot
|
Rbot Reaction plugin allows command execution
|
CWE-20
Improper Input Validation
|
CVE-2010-2446
|
2024-11-21 10:16 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304700
|
7.5 |
HIGH
Network
|
makepasswd_project
|
makepasswd
|
makepasswd 1.10 default settings generate insecure passwords
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2010-2247
|
2024-11-21 10:16 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|