|
306071
|
- |
|
ibm
|
filenet_p8_application_engine
|
Cross-site scripting (XSS) vulnerability in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-016 allows remote attackers to inject arbitrary web script …
|
CWE-79
Cross-site Scripting
|
CVE-2009-4999
|
2024-11-21 10:10 |
2010-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306072
|
- |
|
ibm
|
filenet_p8_application_engine
|
The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-019 and 4.0.2.x before 4.0.2.7-P8AE-FP007, in certain FileTracker configurations, does not apply a secu…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-4998
|
2024-11-21 10:10 |
2010-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306073
|
4.7 |
MEDIUM
Local
|
linux debian canonical
|
linux_kernel debian_linux ubuntu_linux
|
Race condition in the tty_fasync function in drivers/char/tty_io.c in the Linux kernel before 2.6.32.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or p…
|
CWE-362 CWE-476
Race Condition NULL Pointer Dereference
|
CVE-2009-4895
|
2024-11-21 10:10 |
2010-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306074
|
- |
|
gnome
|
power_manager
|
gnome-power-manager 2.27.92 does not properly implement the lock_on_suspend and lock_on_hibernate settings for locking the screen when the suspend or hibernate button is pressed, which might make it …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-4997
|
2024-11-21 10:10 |
2010-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306075
|
- |
|
xfce
|
xfce
|
Xfce4-session 4.5.91 in Xfce does not lock the screen when the suspend or hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-4996
|
2024-11-21 10:10 |
2010-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306076
|
- |
|
twiki
|
twiki
|
Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.2 allows remote attackers to hijack the authentication of arbitrary users for requests that update pages, as demonstrated by a URL …
|
CWE-352
Origin Validation Error
|
CVE-2009-4898
|
2024-11-21 10:10 |
2010-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306077
|
- |
|
smartertools
|
smartertrack
|
Cross-site scripting (XSS) vulnerability in frmTickets.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to inject arbitrary web script or HTML via the email address field. N…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4995
|
2024-11-21 10:10 |
2010-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306078
|
- |
|
smartertools
|
smartertrack
|
Cross-site scripting (XSS) vulnerability in frmKBSearch.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4994
|
2024-11-21 10:10 |
2010-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306079
|
- |
|
script-shop24
|
lm_starmail_paidmail
|
PHP remote file inclusion vulnerability in home.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
|
CWE-94
Code Injection
|
CVE-2009-4993
|
2024-11-21 10:10 |
2010-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306080
|
- |
|
script-shop24
|
lm_starmail_paidmail
|
SQL injection vulnerability in paidbanner.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
|
CWE-89
SQL Injection
|
CVE-2009-4992
|
2024-11-21 10:10 |
2010-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|