|
299321
|
- |
|
google
|
picasa
|
Google Picasa before 3.6 Build 105.67 does not properly handle invalid properties in JPEG images, which allows remote attackers to execute arbitrary code via a crafted image file.
|
CWE-94
Code Injection
|
CVE-2011-2747
|
2024-11-21 10:28 |
2011-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299322
|
- |
|
mod_authnz_external_project debian
|
mod_authnz_external debian_linux
|
SQL injection vulnerability in mysql/mysql-auth.pl in the mod_authnz_external module 3.2.5 and earlier for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the use…
|
CWE-89
SQL Injection
|
CVE-2011-2688
|
2024-11-21 10:28 |
2011-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299323
|
- |
|
joomla
|
joomla\!
|
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the URI to includes/application.php, reachable throug…
|
CWE-79
Cross-site Scripting
|
CVE-2011-2710
|
2024-11-21 10:28 |
2011-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299324
|
- |
|
joomla
|
joomla\!
|
Joomla! before 1.5.23 does not properly check for errors, which allows remote attackers to obtain sensitive information via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2011-2488
|
2024-11-21 10:28 |
2011-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299325
|
- |
|
chyrp
|
chyrp
|
upload_handler.php in the swfupload extension in Chyrp 2.0 and earlier relies on client-side JavaScript code to restrict the file extensions of uploaded files, which allows remote authenticated users…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-2745
|
2024-11-21 10:28 |
2011-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299326
|
- |
|
mega-nerd
|
libsndfile
|
Integer overflow in libsndfile before 1.0.25 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PARIS Audio Format (PAF) file th…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2011-2696
|
2024-11-21 10:28 |
2011-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299327
|
- |
|
drupal
|
drupal
|
Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-2687
|
2024-11-21 10:28 |
2011-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299328
|
- |
|
videolan
|
vlc_media_player
|
Heap-based buffer overflow in the AVI_ChunkRead_strf function in libavi.c in the AVI demuxer in VideoLAN VLC media player before 1.1.11 allows remote attackers to cause a denial of service (applicati…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2011-2588
|
2024-11-21 10:28 |
2011-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299329
|
- |
|
joomla
|
joomla\!
|
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the com_contact component, as dem…
|
CWE-79
Cross-site Scripting
|
CVE-2011-2509
|
2024-11-21 10:28 |
2011-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299330
|
- |
|
videolan
|
vlc_media_player
|
Heap-based buffer overflow in the DemuxAudioSipr function in real.c in the RealMedia demuxer in VideoLAN VLC media player 1.1.x before 1.1.11 allows remote attackers to cause a denial of service (app…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2011-2587
|
2024-11-21 10:28 |
2011-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|