|
301231
|
- |
|
apache
|
tomcat
|
Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-1582
|
2024-11-21 10:26 |
2011-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301232
|
- |
|
trendmicro
|
trend_micro_internet_security
|
The Keystroke Encryption feature in Trend Micro Internet Security 2009 (aka Virus Buster 2009 and PC-cillin 2009) does not completely encrypt passwords, which allows local users to obtain sensitive i…
|
CWE-310
Cryptographic Issues
|
CVE-2011-1327
|
2024-11-21 10:26 |
2011-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301233
|
- |
|
exim
|
exim
|
The DKIM implementation in Exim 4.7x before 4.76 permits matching for DKIM identities to apply to lookup items, instead of only strings, which allows remote attackers to execute arbitrary code or acc…
|
CWE-20
Improper Input Validation
|
CVE-2011-1407
|
2024-11-21 10:26 |
2011-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301234
|
- |
|
mahara
|
mahara
|
Mahara before 1.3.6 does not properly handle an https URL in the wwwroot configuration setting, which makes it easier for user-assisted remote attackers to obtain credentials by sniffing the network …
|
CWE-16
Configuration
|
CVE-2011-1406
|
2024-11-21 10:26 |
2011-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301235
|
- |
|
mahara
|
mahara
|
Cross-site scripting (XSS) vulnerability in Mahara before 1.3.6 allows remote authenticated users to inject arbitrary web script or HTML via vectors associated with HTML e-mail messages, related to a…
|
CWE-79
Cross-site Scripting
|
CVE-2011-1405
|
2024-11-21 10:26 |
2011-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301236
|
- |
|
mahara
|
mahara
|
Mahara before 1.3.6 does not properly restrict the data in responses to AJAX calls, which allows remote authenticated users to obtain sensitive information via a request associated with (1) blocktype…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-1404
|
2024-11-21 10:26 |
2011-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301237
|
- |
|
mahara
|
mahara
|
Cross-site request forgery (CSRF) vulnerability in the pieforms implementation in Mahara before 1.3.6 allows remote attackers to hijack the authentication of arbitrary users for requests to any form,…
|
CWE-352
Origin Validation Error
|
CVE-2011-1403
|
2024-11-21 10:26 |
2011-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301238
|
- |
|
mahara
|
mahara
|
Mahara before 1.3.6 allows remote authenticated users to bypass intended access restrictions, and suspend a user account, edit a view, visit a view, edit a plan artefact, read a plans block, read a p…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-1402
|
2024-11-21 10:26 |
2011-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301239
|
- |
|
fon
|
la_fonera\+_firmware la_fonera\+
|
Unspecified vulnerability on the La Fonera+ router with firmware before 1.7.0.1 allows remote attackers to cause a denial of service via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2011-1326
|
2024-11-21 10:26 |
2011-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301240
|
- |
|
hp
|
palm_webos
|
HP Palm webOS 1.4.5 and 1.4.5.1 does not properly restrict Plug-in Development Kit (PDK) applications, which allows local users to gain privileges by leveraging unintended filesystem write access.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-1738
|
2024-11-21 10:26 |
2011-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|