|
304921
|
- |
|
mozilla
|
bugzilla
|
Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6 and 3.7, when use_suexec is enabled, uses world-readable permissions for the localconfig files, which allows local users to read sensitive configur…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-0180
|
2024-11-21 10:11 |
2010-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304922
|
- |
|
mozilla
|
firefox seamonkey
|
Use-after-free vulnerability in the nsCycleCollector::MarkRoots function in Mozilla Firefox 3.5.x before 3.5.10 and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a craf…
|
CWE-399
Resource Management Errors
|
CVE-2010-0183
|
2024-11-21 10:11 |
2010-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304923
|
- |
|
novell
|
access_manager
|
Directory traversal vulnerability in the getEntry method in the PortalModuleInstallManager component in a servlet in nps.jar in the Administration Console (aka Access Management Console) in Novell Ac…
|
CWE-22
Path Traversal
|
CVE-2010-0284
|
2024-11-21 10:11 |
2010-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304924
|
6.5 |
MEDIUM
Network
|
apache
|
qpid-cpp
|
qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use .
|
CWE-20
Improper Input Validation
|
CVE-2009-5004
|
2024-11-21 10:10 |
2019-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304925
|
6.1 |
MEDIUM
Network
|
pixelpost
|
pixelpost
|
pixelpost 1.7.1 has XSS
|
CWE-79
Cross-site Scripting
|
CVE-2009-4900
|
2024-11-21 10:10 |
2019-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304926
|
9.8 |
CRITICAL
Network
|
pixelpost
|
pixelpost
|
pixelpost 1.7.1 has SQL injection
|
CWE-89
SQL Injection
|
CVE-2009-4899
|
2024-11-21 10:10 |
2019-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304927
|
- |
|
justsystems
|
just_smile atok atok_flat-rate_service
|
Unspecified vulnerability in JustSystems Corporation ATOK 2006 through 2009 and ATOK flat-rate service, and Just Smile 4 with the ATOK Smile module, allows physically proximate users to bypass the sc…
|
NVD-CWE-noinfo
|
CVE-2009-4738
|
2024-11-21 10:10 |
2013-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304928
|
- |
|
mozilla
|
firefox
|
Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8 encoding, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted…
|
CWE-79
Cross-site Scripting
|
CVE-2009-5017
|
2024-11-21 10:10 |
2010-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304929
|
- |
|
php
|
php
|
Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanism…
|
CWE-189
Numeric Errors
|
CVE-2009-5016
|
2024-11-21 10:10 |
2010-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304930
|
- |
|
turbogears
|
turbogears2
|
The URL dispatch mechanism in TurboGears2 (aka tg2) before 2.0.2 exposes controller methods even when an @expose decoration is not used, which has unspecified impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2009-5015
|
2024-11-21 10:10 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|