back abk-soft -- ablespace
|
Multiple cross-site scripting (XSS) vulnerabilities in AbleSpace 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) gid parameter to groups profile.php, (2) cat id and (3) razd id parameters to adv cat.php, and the (4) URL to blogs full.php. | 2009-04-17 | 4.3 | CVE-2009-1315 BID BUGTRAQ MILW0RM MISC
|
back apache -- geronimo
|
Multiple cross-site scripting (XSS) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) ip, (3) username, or (4) description parameter to console/portal/Server/Monitoring; or (5) the PATH INFO to the default URI under console/portal/. | 2009-04-17 | 4.3 | CVE-2009-0038 CONFIRM CONFIRM
|
back apache -- geronimo
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to hijack the authentication of administrators for requests that (1) change the web administration password, (2) upload applications, and perform unspecified other administrative actions, as demonstrated by (3) a Shutdown request to console/portal//Server/Shutdown. | 2009-04-17 | 6.8 | CVE-2009-0039 BID BUGTRAQ CONFIRM CONFIRM MISC
|
back aquacms -- aqua cms
|
Multiple SQL injection vulnerabilities in Aqua CMS 1.1, when magic quotes gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) userSID cookie parameter to droplets/functions/base.php and the (2) username parameter to admin/index.php. | 2009-04-17 | 6.8 | CVE-2009-1317 BID MILW0RM SECUNIA
|
back chcounter -- chcounter
|
Multiple SQL injection vulnerabilities in stats/index.php in chCounter 3.1.3 allow remote attackers to execute arbitrary SQL commands via (1) the login name parameter (aka the username field) or (2) the login pw parameter (aka the password field). | 2009-04-20 | 6.8 | CVE-2009-1347 BID MILW0RM SECUNIA
|
back china-on-site -- flexphplink
|
Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPLink Pro 0.0.6 and 0.0.7, when magic quotes gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the checkuser parameter (aka username field), or (2) the checkpass parameter (aka password field), to admin/index.php. | 2009-04-20 | 6.8 | CVE-2008-6730 XF OSVDB MILW0RM SECUNIA
|
back cisco -- subscriber edge services manager
|
Cross-site scripting (XSS) vulnerability in Cisco Subscriber Edge Services Manager (SESM) allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: some of these details are obtained from third party information. | 2009-04-13 | 4.3 | CVE-2009-1287 MISC BID SECTRACK
|
back cmscout -- cmscout
|
Multiple SQL injection vulnerabilities in CMScout 2.06 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) index.php in a mythings page (mythings.php) and (2) the users page in admin.php. | 2009-04-17 | 6.0 | CVE-2008-6725 XF BID MILW0RM CONFIRM SECUNIA OSVDB
|
back cmscout -- cmscout
|
Multiple directory traversal vulnerabilities in CMScout 2.06, when register globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the bit parameter to (1) admin.php and (2) index.php, different vectors than CVE-2008-3415. | 2009-04-17 | 6.0 | CVE-2008-6726 XF CONFIRM
|
back david cadu -- dcdgooglemap
|
Cross-site scripting (XSS) vulnerability in DCD GoogleMap (dcdgooglemap) 1.1.0 and earlier extension for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | 2009-04-10 | 4.3 | CVE-2008-6687 CONFIRM
|
back drupal -- cck comment reference
|
Cross-site scripting (XSS) vulnerability in the CCK comment reference module 6.x before 6.x-1.2, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via certain comment titles associated with a node edit form. | 2009-04-20 | 4.3 | CVE-2009-1342 VUPEN CONFIRM
|
back drupal -- print
|
Cross-site scripting (XSS) vulnerability in the Print (aka Printer, e-mail and PDF versions) module 5.x before 5.x-4.5 and 6.x before 6.x-1.5, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via content titles. | 2009-04-20 | 4.3 | CVE-2009-1343 VUPEN BID CONFIRM
|
back drupal -- localization client
|
Cross-site scripting (XSS) vulnerability in the Localization client module 5.x before 5.x-1.2 and 6.x before 6.x-1.7, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via input to the translation functionality. | 2009-04-20 | 4.3 | CVE-2009-1344 VUPEN BID CONFIRM
|
back hp -- procurve manager
|
Unspecified vulnerability in HP ProCurve Manager and HP ProCurve Manager Plus 2.3 and earlier allows remote attackers to obtain sensitive information from the ProCurve Manager server via unknown attack vectors. | 2009-04-15 | 5.0 | CVE-2007-4514 XF HP HP
|
back hp -- deskjet 6840
|
Cross-site scripting (XSS) vulnerability in refresh rate.htm in the web interface on the HP Deskjet 6840 printer with firmware XF1M131A allows remote attackers to inject arbitrary web script or HTML via the POST request body. | 2009-04-17 | 4.3 | CVE-2009-1333 XF BUGTRAQ
|
back humayun shabbir bhutta -- asp product catalog
|
Cross-site scripting (XSS) vulnerability in search.asp in ASP Product Catalog 1.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter. | 2009-04-17 | 4.3 | CVE-2009-1321 XF BID MILW0RM
|
back humayun shabbir bhutta -- asp product catalog
|
ASP Product Catalog 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for database/aspProductCatalog.mdb. | 2009-04-17 | 5.0 | CVE-2009-1322 XF MILW0RM
|
back ibm -- lotus domino
|
The IMAP task in the server in IBM Lotus Domino 8.0.2 before FP1 IF1 and 8.5 before IF3 allows remote attackers to cause a denial of service (daemon crash) via a MIME e-mail message with RFC822 attachments (aka blobs) containing malformed root entities. | 2009-04-13 | 5.0 | CVE-2009-1286 CONFIRM CONFIRM
|
back ibm -- advanced management module ibm -- bladecenter
|
Multiple cross-site scripting (XSS) vulnerabilities in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to inject arbitrary web script or HTML via (1) the username in a login action or (2) the PATH parameter to private/file management.ssi in the File manager. | 2009-04-13 | 4.3 | CVE-2009-1288 BID BUGTRAQ MISC SECTRACK OSVDB OSVDB
|
back ibm -- advanced management module ibm -- bladecenter
|
private/login.ssi in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allows remote attackers to discover the access roles and scopes of arbitrary user accounts via a modified WEBINDEX parameter. | 2009-04-13 | 4.0 | CVE-2009-1289 BID BUGTRAQ MISC SECTRACK OSVDB
|
back ibm -- advanced management module ibm -- bladecenter
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration interface in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to hijack the authentication of administrators, as demonstrated by a power-off request to the private/blade power action script. | 2009-04-13 | 6.8 | CVE-2009-1290 BID BUGTRAQ MISC SECTRACK OSVDB
|
back ibm -- tivoli continuous data protection for files
|
Cross-site scripting (XSS) vulnerability in login/FilepathLogin.html in IBM Tivoli Continuous Data Protection (CDP) for Files 3.1.4.0 allows remote attackers to inject arbitrary web script or HTML via the reason parameter. | 2009-04-17 | 4.3 | CVE-2009-1334 XF VUPEN BID OSVDB MISC SECTRACK SECUNIA
|
back jamroom -- jamroom
|
Directory traversal vulnerability in index.php in Jamroom 3.1.2, 3.2.3 through 3.2.6, 4.0.2, and possibly other versions before 3.4.0 allows remote attackers to include arbitrary files via directory traversal sequences in the t parameter. | 2009-04-17 | 6.5 | CVE-2009-1318 XF BID MILW0RM CONFIRM
|
back kernel -- linux-pam
|
Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified. | 2009-04-16 | 4.6 | CVE-2009-0579 FEDORA CONFIRM
|
back liferay -- liferay enterprise portal novell -- teaming
|
Multiple cross-site scripting (XSS) vulnerabilities in web/guest/home in the Liferay 4.3.0 portal in Novell Teaming 1.0 through SP3 (1.0.3) allow remote attackers to inject arbitrary web script or HTML via the (1) p p state or (2) p p mode parameters. | 2009-04-16 | 4.3 | CVE-2009-1294 CONFIRM
|
back microsoft -- forefront threat management gateway microsoft -- internet security and acceleration server
|
The firewall engine in Microsoft Forefront Threat Management Gateway, Medium Business Edition (TMG MBE); and Internet Security and Acceleration (ISA) Server 2004 SP3, 2006, 2006 Supportability Update, and 2006 SP1; does not properly manage the session state of web listeners, which allows remote attackers to cause a denial of service (many stale sessions) via crafted packets, aka "Web Proxy TCP State Limited Denial of Service Vulnerability." | 2009-04-15 | 5.0 | CVE-2009-0077 CERT
|
back microsoft -- windows server 2003 microsoft -- windows xp
|
The RPCSS service in Microsoft Windows XP SP2 and SP3 and Server 2003 SP1 and SP2 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows RPCSS Service Isolation Vulnerability." | 2009-04-15 | 6.9 | CVE-2009-0079 CERT
|
back microsoft -- windows server microsoft -- windows vista
|
The ThreadPool class in Windows Vista Gold and SP1, and Server 2008, does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by leveraging incorrect thread ACLs to access the resources of one of the processes, aka "Windows Thread Pool ACL Weakness Vulnerability." | 2009-04-15 | 6.9 | CVE-2009-0080 CERT
|
back microsoft -- windows 2000 microsoft -- windows server 2003 microsoft -- windows server 2008 microsoft -- windows vista microsoft -- windows xp
|
Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Vista Gold allows remote web servers to impersonate arbitrary https web sites by using DNS spoofing to "forward a connection" to a different https web site that has a valid certificate matching its own domain name, but not a certificate matching the domain name of the host requested by the user, aka "Windows HTTP Services Certificate Name Mismatch Vulnerability." | 2009-04-15 | 5.8 | CVE-2009-0089 CERT
|
back microsoft -- forefront threat management gateway microsoft -- internet security and acceleration server
|
Cross-site scripting (XSS) vulnerability in cookieauth.dll in the HTML forms authentication component in Microsoft Forefront Threat Management Gateway, Medium Business Edition (TMG MBE); and Internet Security and Acceleration (ISA) Server 2006, 2006 Supportability Update, and 2006 SP1; allows remote attackers to inject arbitrary web script or HTML via "authentication input" to this component, aka "Cross-Site Scripting Vulnerability." | 2009-04-15 | 4.3 | CVE-2009-0237 CERT
|
back microsoft -- ie
|
Microsoft Internet Explorer 7 and 8 on Windows XP and Vista allows remote attackers to cause a denial of service (application hang) via a large document composed of unprintable characters, aka MSRC 9011jr. | 2009-04-17 | 4.3 | CVE-2009-1335 BUGTRAQ
|
back myupb -- upb
|
Cross-site scripting (XSS) vulnerability in Ultimate PHP Board (UPB) 2.2.2, 2.2.1, and earlier 2.x versions allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header. | 2009-04-20 | 4.3 | CVE-2008-6727 XF BID MILW0RM SECUNIA OSVDB
|
back novell -- teaming
|
The web login functionality (c/portal/login) in Novell Teaming 1.0 through SP3 (1.0.3) generates different error messages depending on whether the username is valid or invalid, which makes it easier for remote attackers to enumerate usernames. | 2009-04-16 | 5.0 | CVE-2009-1293 CONFIRM
|
back ntp -- ntp
|
Stack-based buffer overflow in the cookedprint function in ntpq/ntpq.c in ntpq in NTP before 4.2.4p7-RC2 allows remote NTP servers to execute arbitrary code via a crafted response. | 2009-04-14 | 6.8 | CVE-2009-0159 CONFIRM BID
|
back oracle -- database 10g oracle -- database 11g oracle -- database 9i
|
Unspecified vulnerability in the Workspace Manager component in Oracle Database 11.1.0.6, 11.1.0.7, 10.2.0.3, 10.2.0.4, 10.1.0.5, 9.2.0.8, and 9.2.0.8DV allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. | 2009-04-15 | 6.5 | CVE-2009-0972 CERT
|
back oracle -- database 10g
|
Unspecified vulnerability in the Cluster Ready Services component in Oracle Database 10.1.0.5 allows remote attackers to affect availability via unknown vectors. | 2009-04-15 | 5.0 | CVE-2009-0973 CERT
|
back oracle -- application server 10g
|
Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors. | 2009-04-15 | 4.3 | CVE-2009-0974 CERT
|
back oracle -- database 10g oracle -- database 11g
|
Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. | 2009-04-15 | 5.5 | CVE-2009-0975 CERT
|
back oracle -- database 10g oracle -- database 11g
|
Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to LTADM. | 2009-04-15 | 5.5 | CVE-2009-0976 CERT
|
back oracle -- database 10g oracle -- database 9i
|
Unspecified vulnerability in the Advanced Queuing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity, related to DBMS AQIN. | 2009-04-15 | 5.5 | CVE-2009-0977 CERT
|
back oracle -- database 10g oracle -- database 11g
|
Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. | 2009-04-15 | 5.5 | CVE-2009-0978 CERT
|
back oracle -- database 10g oracle -- database 11g
|
Unspecified vulnerability in the SQLX Functions component in Oracle Database 10.2.0.3 and 11.1.0.6 allows remote authenticated users to affect integrity and availability, related to AGGXQIMP. | 2009-04-15 | 5.5 | CVE-2009-0980 CERT
|
back oracle -- database 11g
|
Unspecified vulnerability in the Application Express component in Oracle Database 11.1.0.7 allows remote authenticated users to affect confidentiality, related to APEX. | 2009-04-15 | 4.0 | CVE-2009-0981 CERT
|
back oracle -- jd edwards enterpriseone oracle -- peoplesoft enterprise
|
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.49.19 allows remote authenticated users to affect integrity via unknown vectors. | 2009-04-15 | 4.0 | CVE-2009-0982 CERT
|
back oracle -- application server 10g
|
Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2009-0974. | 2009-04-15 | 4.3 | CVE-2009-0983 CERT
|
back oracle -- database 10g oracle -- database 11g oracle -- database 9i
|
Unspecified vulnerability in the Database Vault component in Oracle Database 9.2.0.8DV, 10.2.0.4, and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to DBMS SYS SQL. | 2009-04-15 | 5.5 | CVE-2009-0984 CERT
|
back oracle -- database 10g oracle -- database 11g
|
Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 and 11.1.0.6 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. | 2009-04-15 | 5.4 | CVE-2009-0986 CERT
|
back oracle -- application server oracle -- application server 10g
|
Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2.1, and 10.1.3.3.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. | 2009-04-15 | 5.5 | CVE-2009-0989 CERT
|
back oracle -- application server oracle -- application server 10g
|
Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2.1, and 10.1.3.3.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. | 2009-04-15 | 5.5 | CVE-2009-0990 CERT
|
back oracle -- database 10g oracle -- database 11g oracle -- database 9i
|
Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect availability via unknown vectors. | 2009-04-15 | 5.0 | CVE-2009-0991 CERT
|
back oracle -- database 10g oracle -- database 11g
|
Unspecified vulnerability in the Advanced Queuing component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality and integrity, related to DBMS AQIN. | 2009-04-15 | 5.5 | CVE-2009-0992 CERT
|
back oracle -- application server oracle -- application server 10g
|
Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2.1, 10.1.3.3.3, and 10.1.3.4 allows remote authenticated users to affect confidentiality via unknown vectors. | 2009-04-15 | 4.0 | CVE-2009-0994 CERT
|
back oracle -- e-business suite oracle -- e-business suite 12
|
Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 12.0.6 and 11i10CU2 allows remote attackers to affect integrity via unknown vectors. | 2009-04-15 | 4.3 | CVE-2009-0995 CERT
|
back oracle -- application server 10g
|
Unspecified vulnerability in the BI Publisher component in Oracle Application Server 10.1.3.2.1, 10.1.3.3.3, and 10.1.3.4 allows remote authenticated users to affect confidentiality via unknown vectors. | 2009-04-15 | 4.0 | CVE-2009-0996 CERT
|
back oracle -- database 11g
|
Unspecified vulnerability in the Database Vault component in Oracle Database 11.1.0.6 allows remote authenticated users to affect confidentiality, related to DBMS SYS SQL. | 2009-04-15 | 4.0 | CVE-2009-0997 CERT
|
back oracle -- jd edwards enterpriseone oracle -- peoplesoft enterprise
|
Unspecified vulnerability in the PeopleSoft Enterprise HRMS - eBenefits component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.9.18 and 9.0.8 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. | 2009-04-15 | 5.5 | CVE-2009-0998 CERT
|
back oracle -- e-business suite
|
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | 2009-04-15 | 6.8 | CVE-2009-0999 CERT
|
back oracle -- bea product suite
|
Unspecified vulnerability in the WebLogic Portal component in BEA Product Suite 8.1 SP6 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. | 2009-04-15 | 5.5 | CVE-2009-1001 CERT
|
back oracle -- bea product suite
|
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality and integrity via unknown vectors. | 2009-04-15 | 5.8 | CVE-2009-1002 CERT
|
back oracle -- bea product suite
|
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, and 9.0 allows remote attackers to affect integrity via unknown vectors. | 2009-04-15 | 5.0 | CVE-2009-1003 CERT
|
back oracle -- bea product suite
|
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote attackers to affect confidentiality and integrity via unknown vectors. | 2009-04-15 | 4.0 | CVE-2009-1004 CERT
|
back oracle -- bea product suite
|
Unspecified vulnerability in the Oracle Data Service Integrator (AquaLogic Data Services Platform) component in BEA Product Suite 10.3.0, 3.2, 3.0.1, and 3.0 allows local users to affect confidentiality, integrity, and availability via unknown vectors. | 2009-04-15 | 4.1 | CVE-2009-1005 CERT
|
back oracle -- application server
|
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML. | 2009-04-15 | 4.4 | CVE-2009-1008 CERT
|
back oracle -- application server
|
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.1.9 allows local users to affect confidentiality, integrity, and availability, related to HTML. | 2009-04-15 | 4.4 | CVE-2009-1009 CERT
|
back oracle -- application server
|
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML. | 2009-04-15 | 4.4 | CVE-2009-1010 CERT
|
back oracle -- application server
|
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML. | 2009-04-15 | 4.4 | CVE-2009-1011 CERT
|
back oracle -- jd edwards enterpriseone oracle -- peoplesoft enterprise
|
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.49.19 allows remote attackers to affect confidentiality and integrity via unknown vectors. | 2009-04-15 | 6.4 | CVE-2009-1013 CERT
|
back oracle -- jd edwards enterpriseone oracle -- peoplesoft enterprise
|
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.49.19 allows remote attackers to affect confidentiality and integrity via unknown vectors. | 2009-04-15 | 5.8 | CVE-2009-1014 CERT
|
back oracle -- application server oracle -- application server 10g
|
Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2.1, 10.1.3.3.3, and 10.1.3.4 allows remote authenticated users to affect confidentiality via unknown vectors. | 2009-04-15 | 4.0 | CVE-2009-1017 CERT
|
back patrick matthai -- pnopaste
|
Cross-site scripting (XSS) vulnerability in index.pl in Perl Nopaste 1.0 allows remote attackers to inject arbitrary web script or HTML via the language parameter. NOTE: some of these details are obtained from third party information. | 2009-04-17 | 4.3 | CVE-2008-6724 BID CONFIRM
|
back phpmotion -- phpmotion
|
Multiple cross-site request forgery (CSRF) vulnerabilities in password.php in PHPmotion 2.1 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests that modify an account via the (1) password or (2) email address parameter. | 2009-04-20 | 6.8 | CVE-2008-6729 XF MILW0RM SECUNIA OSVDB
|
back sun -- openjdk
|
Integer overflow in the PulseAudioTargetDataL class in src/java/org/classpath/icedtea/pulseaudio/PulseAudioTargetDataLine.java in Pulse-Java, as used in OpenJDK 1.6.0.0 and other products, allows remote attackers to cause a denial of service (applet crash) via a crafted Pulse Audio source data line. | 2009-04-13 | 5.0 | CVE-2009-0794 FEDORA FEDORA CONFIRM VUPEN SECUNIA MLIST
|
back sun -- java system directory server
|
The Online Help feature in Sun Java System Directory Server 5.2 and Enterprise Edition 5 allows remote attackers to determine the existence of files and directories, and possibly obtain partial contents of files, via unspecified vectors. | 2009-04-17 | 5.0 | CVE-2009-1332 BID SUNALERT SECUNIA
|
back wireshark -- wireshark
|
Unspecified vulnerability in the LDAP dissector in Wireshark 0.99.2 through 1.0.6, when running on Windows, allows remote attackers to cause a denial of service (crash) via unknown attack vectors. | 2009-04-13 | 5.0 | CVE-2009-1267 CONFIRM
|
back wireshark -- wireshark
|
The Check Point High-Availability Protocol (CPHAP) dissector in Wireshark 0.9.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted FWHA MY STATE packet. | 2009-04-13 | 4.3 | CVE-2009-1268 MISC XF CONFIRM SECTRACK BID MANDRIVA
|
back wireshark -- wireshark
|
Unspecified vulnerability in Wireshark 0.99.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted Tektronix .rf5 file. | 2009-04-13 | 5.0 | CVE-2009-1269 XF CONFIRM SECTRACK BID MANDRIVA
|
back yourfreeworld -- apartment search script
|
Cross-site scripting (XSS) vulnerability in listtest.php in Apartment Search Script allows remote attackers to inject arbitrary web script or HTML via the r parameter. | 2009-04-10 | 4.3 | CVE-2008-6683 XF BID MILW0RM
|
back zazzle -- store builder
|
Multiple cross-site scripting (XSS) vulnerabilities in include/zstore.php in Zazzle Store Builder 1.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) gridPage and (2) gridSort parameters. NOTE: some of these details are obtained from third party information. | 2009-04-17 | 4.3 | CVE-2009-1320 BID SECUNIA MISC
|