back .t-dreams -- job career package
|
Techno Dreams Job Career Package 3.0 allows remote attackers to bypass authentication and obtain administrative access by setting the JobCareerAdmin cookie to Login. | 2009-05-15 | 7.5 | CVE-2009-1638 XF BID MILW0RM SECUNIA OSVDB
|
back apple -- safari
|
Apple Safari executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF file, which might allow remote attackers to bypass intended Adobe Acrobat JavaScript restrictions on accessing the document object, as demonstrated by a web site that permits PDF uploads by untrusted users, and therefore has a shared document.domain between the web site and this javascript: URI. NOTE: the researcher reports that Adobe's position is "a PDF file is active content." | 2009-05-11 | 9.3 | CVE-2009-1600 BUGTRAQ MISC
|
back apple -- mac os x apple -- mac os x server
|
The kernel in Apple Mac OS X 10.5 before 10.5.7 does not properly check indexes during the handling of workqueues, which allows local users to gain privileges or cause a denial of service (system shutdown) via unspecified vectors. | 2009-05-13 | 7.2 | CVE-2008-1517 CONFIRM APPLE
|
back apple -- mac os x
|
Integer underflow in QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image that triggers a heap-based buffer overflow. | 2009-05-13 | 9.3 | CVE-2009-0010 CONFIRM APPLE
|
back apple -- mac os x apple -- mac os x server
|
Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows local users to gain privileges or cause a denial of service (application crash) by attempting to mount a crafted sparse disk image that triggers memory corruption. | 2009-05-13 | 7.5 | CVE-2009-0149 CONFIRM APPLE
|
back apple -- safari
|
WebKit, as used in Safari before 3.2.3 and 4 Public Beta, on Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 and Windows allows remote attackers to execute arbitrary code via a crafted SVGList object that triggers memory corruption. | 2009-05-13 | 9.3 | CVE-2009-0945 CONFIRM APPLE APPLE APPLE
|
back baofeng -- storm
|
Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote attackers to execute arbitrary code via a long argument to the OnBeforeVideoDownload method. NOTE: some of these details are obtained from third party information. | 2009-05-11 | 9.3 | CVE-2009-1612 BID
|
back carnegie mellon university -- cyrus-sasl
|
Multiple buffer overflows in the CMU Cyrus SASL library before 2.1.23 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via strings that are used as input to the sasl encode64 function in lib/saslutil.c. | 2009-05-15 | 7.5 | CVE-2009-0688 CERT-VN BID CONFIRM
|
back cisco -- wvc54gc
|
The Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 stores passwords and wireless-network keys in cleartext in (1) pass wd.htm and (2) Wsecurity.htm, which allows remote attackers to obtain sensitive information by reading the HTML source code. | 2009-05-06 | 7.8 | CVE-2009-1560 XF VUPEN MISC
|
back cscope -- cscope
|
Multiple buffer overflows in Cscope before 15.7a allow remote attackers to execute arbitrary code via long strings in input such as (1) source-code tokens and (2) pathnames, related to integer overflows in some cases. NOTE: this issue exists because of an incomplete fix for CVE-2004-2541. | 2009-05-05 | 9.3 | CVE-2009-0148 CONFIRM CONFIRM
|
back cscope -- cscope
|
Multiple stack-based buffer overflows in the putstring function in find.c in Cscope before 15.6 allow user-assisted remote attackers to execute arbitrary code via a long (1) function name or (2) symbol in a source-code file. | 2009-05-07 | 9.3 | CVE-2009-1577 CONFIRM CONFIRM CONFIRM
|
back dafolo -- dafolocontrol
|
Multiple stack-based and heap-based buffer overflows in Dafolo DafoloControl ActiveX control (DafoloFFControl.dll) 1.108.6.195 allow remote attackers to execute arbitrary code via long (1) baseurl, (2) kommune, (3) felter, (4) afdeling, (5) Flags, (6) HelpURL, (7) caburl, or (8) filename properties; or (9) a long argument to the Open method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2009-05-11 | 9.3 | CVE-2009-1606 XF XF XF XF BID SECUNIA
|
back ecshop -- ecshop
|
SQL injection vulnerability in user.php in EcShop 2.5.0 allows remote attackers to execute arbitrary SQL commands via the order sn parameter in an order query action. | 2009-05-12 | 7.5 | CVE-2009-1622 BID MILW0RM
|
back electrasoft -- 32bit ftp
|
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long banner. NOTE: this might overlap CVE-2003-1368. | 2009-05-08 | 10.0 | CVE-2009-1592 BID MILW0RM MILW0RM
|
back electrasoft -- 32bit ftp
|
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long 257 reply to a CWD command. | 2009-05-11 | 10.0 | CVE-2009-1611 BID MILW0RM
|
back garmin -- garmin communicator plugin
|
The domain-locking implementation in the GARMINAXCONTROL.GarminAxControl t.1 ActiveX control in npGarmin.dll in the Garmin Communicator Plug-In 2.6.4.0 does not properly enforce the restrictions that (1) download and (2) upload requests come from a web site specified by the user, which allows remote attackers to obtain sensitive information or reconfigure Garmin GPS devices via unspecified vectors related to a "synchronisation error." | 2009-05-11 | 9.3 | CVE-2009-0194 XF BID BUGTRAQ SECTRACK MISC SECUNIA OSVDB
|
back google -- chrome
|
Heap-based buffer overflow in the ParamTraits::Read function in Google Chrome before 1.0.154.64 allows attackers to leverage renderer access to cause a denial of service (application crash) or possibly execute arbitrary code via vectors related to a large bitmap that arrives over the IPC channel. | 2009-05-07 | 9.3 | CVE-2009-1441 CONFIRM CONFIRM
|
back google -- chrome
|
Google Chrome executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF file, which might allow remote attackers to bypass intended Adobe Acrobat JavaScript restrictions on accessing the document object, as demonstrated by a web site that permits PDF uploads by untrusted users, and therefore has a shared document.domain between the web site and this javascript: URI. NOTE: the researcher reports that Adobe's position is "a PDF file is active content." | 2009-05-11 | 9.3 | CVE-2009-1598 BUGTRAQ MISC
|
back hp -- openview network node manager
|
Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via unknown vectors. | 2009-05-05 | 10.0 | CVE-2009-0720 HP HP
|
back hp -- data protector express
|
Unspecified vulnerability in HP Data Protector Express and Express SSE 3.x before build 47065, and Express and Express SSE 4.x before build 46537, allows local users to gain privileges or cause a denial of service via unknown vectors. | 2009-05-14 | 7.2 | CVE-2009-0714 SECUNIA HP HP
|
back ibiblio -- osprey
|
PHP remote file inclusion vulnerability in ListRecords.php in osprey 1.0a4.1 allows remote attackers to execute arbitrary PHP code via a URL in the xml dir parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: the lib dir vector is already covered by CVE-2006-6630. | 2009-05-12 | 7.5 | CVE-2008-6807 XF BID
|
back ibm -- tivoli storage manager client ibm -- tivoli storage manager express
|
Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, and 5.4.0.0 through 5.4.1.96, and the TSM Express client 5.3.3.0 through 5.3.6.4, allow remote attackers to execute arbitrary code via (1) a request packet that is not properly parsed by an unspecified "generic string handling function" or (2) a crafted NodeName in a dicuGetIdentifyRequest request packet, related to the (a) Web GUI and (b) Java GUI. | 2009-05-05 | 10.0 | CVE-2008-4828 AIXAPAR CONFIRM
|
back ibm -- tivoli storage manager client ibm -- tivoli storage manager express
|
Buffer overflow in the Web GUI in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, 5.4.0.0 through 5.4.2.6, and 5.5.0.0 through 5.5.1.17 allows attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors. | 2009-05-05 | 10.0 | CVE-2009-1520 XF VUPEN AIXAPAR CONFIRM SECUNIA
|
back ibm -- tivoli storage manager client ibm -- tivoli storage manager express
|
Unspecified vulnerability in the Java GUI in the IBM Tivoli Storage Manager (TSM) client 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.5, 5.4.0.0 through 5.4.2.6, and 5.5.0.0 through 5.5.1.17, and the TSM Express client 5.3.3.0 through 5.3.6.5, allows attackers to read or modify arbitrary files via unknown vectors. | 2009-05-05 | 7.5 | CVE-2009-1521 AIXAPAR CONFIRM
|
back ibm -- tivoli storage manager client
|
The IBM Tivoli Storage Manager (TSM) client 5.5.0.0 through 5.5.1.17 on AIX and Windows, when SSL is used, allows remote attackers to conduct unspecified man-in-the-middle attacks and read arbitrary files via unknown vectors. | 2009-05-05 | 7.1 | CVE-2009-1522 AIXAPAR CONFIRM
|
back jobscript -- job script job board software
|
admin/changepassword.php in Job Script Job Board Software 2.0 allows remote attackers to change the administrator password and gain administrator privileges via a direct request. | 2009-05-11 | 7.5 | CVE-2009-1610 XF BID MILW0RM SECUNIA OSVDB
|
back klinzmann -- application access server
|
Application Access Server (A-A-S) 2.0.48 has "wildbat" as its default password for the admin account, which makes it easier for remote attackers to obtain access. | 2009-05-14 | 7.5 | CVE-2009-1465 MISC BID BUGTRAQ SECTRACK
|
back kowalczyk -- sumatrapdf
|
Heap-based buffer overflow in the loadexponentialfunc function in mupdf/pdf function.c in MuPDF in the mupdf-20090223-win32 package, as used in SumatraPDF 0.9.3 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF file. NOTE: some of these details are obtained from third party information. | 2009-05-11 | 9.3 | CVE-2009-1605 VUPEN VUPEN SECUNIA FULLDISC
|
back limesurvey -- limesurvey
|
Unspecified vulnerability in LimeSurvey before 1.82 allows remote attackers to execute commands and obtain sensitive data via unknown attack vectors related to /admin/remotecontrol/. | 2009-05-11 | 7.5 | CVE-2009-1604 VUPEN CONFIRM
|
back mcafee -- groupshield
|
McAfee GroupShield for Microsoft Exchange on Exchange Server 2000, and possibly other anti-virus or anti-spam products from McAfee or other vendors, does not scan X- headers for malicious content, which allows remote attackers to bypass virus detection via a crafted message, as demonstrated by a message with an X-Testing header and no message body. | 2009-05-05 | 10.0 | CVE-2009-1491 XF MISC
|
back microchip -- mplab ide
|
Multiple buffer overflows in Microchip MPLAB IDE 8.30 and possibly earlier versions allow user-assisted remote attackers to execute arbitrary code via a .MCP project file with long (1) FILE INFO, (2) CAT FILTERS, and possibly other fields. | 2009-05-11 | 9.3 | CVE-2009-1608 BID BUGTRAQ MISC SECUNIA
|
back microsoft -- office powerpoint
|
Multiple stack-based buffer overflows in the PowerPoint 4.0 importer (PP4X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allow remote attackers to execute arbitrary code via crafted formatting data for paragraphs in a file that uses a PowerPoint 4.0 native file format, related to (1) an incorrect calculation from a record header, or (2) an interget that is used to specify the number of bytes to copy, aka "Legacy File Format Vulnerability." | 2009-05-12 | 9.3 | CVE-2009-0220 CERT
|
back microsoft -- office powerpoint
|
Integer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via an invalid record type in a PowerPoint file that triggers memory corruption, aka "Integer Overflow Vulnerability." | 2009-05-12 | 9.3 | CVE-2009-0221 CERT
|
back microsoft -- office powerpoint
|
Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to a "pointer overwrite" and memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0223, CVE-2009-0226, CVE-2009-0227, and CVE-2009-1137. | 2009-05-12 | 9.3 | CVE-2009-0222 CERT
|
back microsoft -- office powerpoint
|
Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0226, CVE-2009-0227, and CVE-2009-1137. | 2009-05-12 | 9.3 | CVE-2009-0223 CERT
|
back microsoft -- compatibility pack word excel powerpoint microsoft -- office compatibility pack for word excel ppt 2007 microsoft -- office powerpoint microsoft -- office powerpoint viewer microsoft -- open xml file format converter microsoft -- powerpoint microsoft -- works
|
Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; PowerPoint Viewer 2003 and 2007 SP1 and SP2; PowerPoint in Microsoft Office 2004 for Mac and 2008 for Mac; Open XML File Format Converter for Mac; Microsoft Works 8.5 and 9.0; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly validate list records in PowerPoint files, which allows remote attackers to execute arbitrary code via a crafted file that triggers memory corruption related to an invalid record type, aka "Memory Corruption Vulnerability." | 2009-05-12 | 9.3 | CVE-2009-0224 CERT
|
back microsoft -- office powerpoint
|
Microsoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to improper "array indexing" and memory corruption, aka "PP7 Memory Corruption Vulnerability." | 2009-05-12 | 9.3 | CVE-2009-0225 CERT
|
back microsoft -- office powerpoint
|
Stack-based buffer overflow in the PowerPoint 4.2 conversion filter in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via a long string in sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0227, and CVE-2009-1137. | 2009-05-12 | 9.3 | CVE-2009-0226 CERT
|
back microsoft -- office powerpoint
|
Stack-based buffer overflow in the PowerPoint 4.2 conversion filter (PP4X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via a large number of structures in sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0226, and CVE-2009-1137. | 2009-05-12 | 9.3 | CVE-2009-0227 CERT
|
back microsoft -- office powerpoint
|
Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to memory corruption, aka "PP7 Memory Corruption Vulnerability," a different vulnerability than CVE-2009-1129. | 2009-05-12 | 9.3 | CVE-2009-1128 CERT
|
back microsoft -- office powerpoint
|
Multiple stack-based buffer overflows in the PowerPoint 95 importer (PP7X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allow remote attackers to execute arbitrary code via an inconsistent record length in sound data in a file that uses a PowerPoint 95 (PPT95) native file format, aka "PP7 Memory Corruption Vulnerability," a different vulnerability than CVE-2009-1128. | 2009-05-12 | 9.3 | CVE-2009-1129 CERT
|
back microsoft -- office microsoft -- office powerpoint
|
Heap-based buffer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a crafted structure in a Notes container in a PowerPoint file that causes PowerPoint to read more data than was allocated when creating a C++ object, leading to an overwrite of a function pointer, aka "Heap Corruption Vulnerability." | 2009-05-12 | 9.3 | CVE-2009-1130 CERT MISC VUPEN SECTRACK BID BUGTRAQ MS SECUNIA
|
back microsoft -- office powerpoint
|
Multiple stack-based buffer overflows in Microsoft Office PowerPoint 2000 SP3 allow remote attackers to execute arbitrary code via a large amount of data associated with unspecified atoms in a PowerPoint file that triggers memory corruption, aka "Data Out of Bounds Vulnerability." | 2009-05-12 | 10.0 | CVE-2009-1131 CERT VUPEN SECTRACK BID BUGTRAQ MS MISC SECUNIA
|
back microsoft -- office powerpoint
|
Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0226, and CVE-2009-0227. | 2009-05-12 | 9.4 | CVE-2009-1137 CERT XF VUPEN SECTRACK BID MS SECUNIA
|
back mini-stream -- mini-stream rm downloader
|
Multiple stack-based buffer overflows in Mini-stream Ripper 3.0.1.1 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram file and (2) a long string in the HREF attribute of a REF element in a .asx file. | 2009-05-15 | 9.3 | CVE-2009-1641 XF BID BID MILW0RM MILW0RM
|
back mini-stream -- mini-stream to mp3 converter
|
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram file and (2) a long string in the HREF attribute of a REF element in a .asx file. | 2009-05-15 | 9.3 | CVE-2009-1642 XF BID BID MILW0RM MILW0RM
|
back mini-stream -- easy rm-mp3 converter
|
Multiple stack-based buffer overflows in Mini-stream Easy RM-MP3 Converter 3.0.0.7 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram file and (2) a long string in the HREF attribute of a REF element in a .asx file. | 2009-05-15 | 9.3 | CVE-2009-1645 XF BID BID MILW0RM MILW0RM
|
back mini-stream -- mini-stream rm downloader
|
Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a long rtsp URL in a .ram file. | 2009-05-15 | 9.3 | CVE-2009-1646 BID MILW0RM
|
back mozilla -- firefox
|
Mozilla Firefox executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF file, which might allow remote attackers to bypass intended Adobe Acrobat JavaScript restrictions on accessing the document object, as demonstrated by a web site that permits PDF uploads by untrusted users, and therefore has a shared document.domain between the web site and this javascript: URI. NOTE: the researcher reports that Adobe's position is "a PDF file is active content." | 2009-05-11 | 9.3 | CVE-2009-1597 BUGTRAQ MISC
|
back nucleustechnologies -- kernel recovery
|
Stack-based buffer overflow in Nucleus Data Recovery Kernel Recovery for Macintosh 4.04 allows user-assisted attackers to execute arbitrary code via a crafted .AMHH file. | 2009-05-15 | 9.3 | CVE-2009-1640 XF BID MISC MISC SECUNIA OSVDB
|
back opera -- opera browser
|
Opera executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF file, which might allow remote attackers to bypass intended Adobe Acrobat JavaScript restrictions on accessing the document object, as demonstrated by a web site that permits PDF uploads by untrusted users, and therefore has a shared document.domain between the web site and this javascript: URI. NOTE: the researcher reports that Adobe's position is "a PDF file is active content." | 2009-05-11 | 9.3 | CVE-2009-1599 BUGTRAQ MISC
|
back qsix -- blusky cms
|
SQL injection vulnerability in index.php in BluSky CMS allows remote attackers to execute arbitrary SQL commands via the news id parameter in a read action. | 2009-05-06 | 7.5 | CVE-2009-1548 VUPEN MILW0RM SECUNIA OSVDB
|
back qt-cute -- quickteam
|
Multiple PHP remote file inclusion vulnerabilities in Qt quickteam 2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) qte web path parameter to qte web.php and the (2) qte root parameter to bin/qte init.php. | 2009-05-06 | 7.5 | CVE-2009-1551 VUPEN MILW0RM SECUNIA OSVDB OSVDB
|
back scripts-for-sites -- ez link directory
|
SQL injection vulnerability in links.php in Scripts for Sites (SFS) EZ Link Directory allows remote attackers to execute arbitrary SQL commands via the cat id parameter in a list action. | 2009-05-12 | 7.5 | CVE-2008-6808 BID MILW0RM
|
back sdp multimedia -- streaming download project
|
Stack-based buffer overflow in Streaming Download Project (SDP) Downloader 2.3.0 allows remote attackers to execute arbitrary code via a long .asf URL in the HREF attribute of a REF element in a .asx file. | 2009-05-12 | 9.3 | CVE-2009-1627 VUPEN BID MILW0RM MILW0RM SECUNIA OSVDB
|
back sorinara -- soritong mp3 player
|
Stack-based buffer overflow in Sorinara Soritong MP3 Player 1.0 allows remote attackers to execute arbitrary code via a crafted .m3u file. | 2009-05-15 | 9.3 | CVE-2009-1643 XF BID MILW0RM
|
back sorinara -- streaming audio player
|
Stack-based buffer overflow in Sorinara Streaming Audio Player 0.9 allows remote attackers to execute arbitrary code via a crafted .pla file. | 2009-05-15 | 9.3 | CVE-2009-1644 XF BID MILW0RM MILW0RM
|
back squirrelmail -- squirrelmail
|
Session fixation vulnerability in SquirrelMail before 1.4.18 allows remote attackers to hijack web sessions via a crafted cookie. | 2009-05-14 | 7.6 | CVE-2009-1580 VUPEN CONFIRM CONFIRM
|
back teraway -- linktracker
|
Teraway LinkTracker 1.0 allows remote attackers to bypass authentication and gain administrative access via a userid=1&lvl=1 value for the twLTadmin cookie. | 2009-05-12 | 7.5 | CVE-2009-1617 BID MILW0RM SECUNIA
|
back teraway -- livehelp
|
Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&lvl=1&usr=&alias=admin&userid=1 value for the TWLHadmin cookie. | 2009-05-12 | 7.5 | CVE-2009-1618 BID MILW0RM SECUNIA
|
back teraway -- filestream
|
Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the twFSadmin cookie to 1. | 2009-05-12 | 7.5 | CVE-2009-1619 BID MILW0RM SECUNIA
|
back tribiq -- tribiq cms
|
** DISPUTED ** Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the COOKIE LAST ADMIN USER and COOKIE LAST ADMIN LANG cookies. NOTE: a third party reports that the vendor disputes the existence of this issue. | 2009-05-11 | 7.5 | CVE-2008-6804 XF BID MILW0RM
|
back ultrafunk -- popcorn
|
Heap-based buffer overflow in popcorn.exe in Ultrafunk Popcorn 1.87 allows remote POP3 servers to cause a denial of service (application crash) via a long string in a +OK response. NOTE: some of these details are obtained from third party information. | 2009-05-15 | 9.3 | CVE-2009-1647 VUPEN BID MILW0RM
|
back will kraft -- ez-blog
|
SQL injection vulnerability in public/specific.php in EZ-Blog before Beta 2 20090427, when magic quotes gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the category parameter. | 2009-05-12 | 7.5 | CVE-2009-1626 BID MILW0RM CONFIRM
|
back yigit aybuga -- dizi portali
|
SQL injection vulnerability in diziler.asp in Yigit Aybuga Dizi Portali allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2009-05-11 | 7.5 | CVE-2008-6803 XF BID
|