Show filters
136 Total Results
Displaying 111-120 of 136
Sort by:
Attacker Value
Unknown
CVE-2011-3848
Disclosure Date: October 27, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Signing Request (CSR) to arbitrary locations via (1) a double-encoded key parameter in the URI in 2.7.x, (2) the CN in the Subject of a CSR in 2.6 and 0.25.
0
Attacker Value
Unknown
CVE-2011-3869
Disclosure Date: October 27, 2011 (last updated October 04, 2023)
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5login file.
0
Attacker Value
Unknown
CVE-2011-3871
Disclosure Date: October 27, 2011 (last updated October 04, 2023)
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local users to run arbitrary Puppet code or trick a user into editing arbitrary files.
0
Attacker Value
Unknown
CVE-2011-3870
Disclosure Date: October 27, 2011 (last updated October 04, 2023)
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attack on the SSH authorized_keys file.
0
Attacker Value
Unknown
CVE-2009-4008
Disclosure Date: June 02, 2011 (last updated October 04, 2023)
Unbound before 1.4.4 does not send responses for signed zones after mishandling an unspecified query, which allows remote attackers to cause a denial of service (DNSSEC outage) via a crafted query.
0
Attacker Value
Unknown
CVE-2011-1922
Disclosure Date: May 31, 2011 (last updated October 04, 2023)
daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and the interface-automatic option are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DNS request that triggers improper error handling.
0
Attacker Value
Unknown
CVE-2010-1953
Disclosure Date: May 19, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the iNetLanka Multiple Map (com_multimap) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
0
Attacker Value
Unknown
CVE-2010-1954
Disclosure Date: May 19, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the iNetLanka Multiple root (com_multiroot) component 1.0 and 1.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2010-1723
Disclosure Date: May 04, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the iNetLanka Contact Us Draw Root Map (com_drawroot) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
0
Attacker Value
Unknown
CVE-2010-0969
Disclosure Date: March 16, 2010 (last updated October 04, 2023)
Unbound before 1.4.3 does not properly align structures on 64-bit platforms, which allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.
0