Show filters
136 Total Results
Displaying 111-120 of 136
Sort by:
Attacker Value
Unknown

CVE-2011-3848

Disclosure Date: October 27, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Signing Request (CSR) to arbitrary locations via (1) a double-encoded key parameter in the URI in 2.7.x, (2) the CN in the Subject of a CSR in 2.6 and 0.25.
0
Attacker Value
Unknown

CVE-2011-3869

Disclosure Date: October 27, 2011 (last updated October 04, 2023)
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5login file.
0
Attacker Value
Unknown

CVE-2011-3871

Disclosure Date: October 27, 2011 (last updated October 04, 2023)
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local users to run arbitrary Puppet code or trick a user into editing arbitrary files.
0
Attacker Value
Unknown

CVE-2011-3870

Disclosure Date: October 27, 2011 (last updated October 04, 2023)
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attack on the SSH authorized_keys file.
0
Attacker Value
Unknown

CVE-2009-4008

Disclosure Date: June 02, 2011 (last updated October 04, 2023)
Unbound before 1.4.4 does not send responses for signed zones after mishandling an unspecified query, which allows remote attackers to cause a denial of service (DNSSEC outage) via a crafted query.
0
Attacker Value
Unknown

CVE-2011-1922

Disclosure Date: May 31, 2011 (last updated October 04, 2023)
daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and the interface-automatic option are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DNS request that triggers improper error handling.
0
Attacker Value
Unknown

CVE-2010-1953

Disclosure Date: May 19, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the iNetLanka Multiple Map (com_multimap) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
0
Attacker Value
Unknown

CVE-2010-1954

Disclosure Date: May 19, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the iNetLanka Multiple root (com_multiroot) component 1.0 and 1.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2010-1723

Disclosure Date: May 04, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the iNetLanka Contact Us Draw Root Map (com_drawroot) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
0
Attacker Value
Unknown

CVE-2010-0969

Disclosure Date: March 16, 2010 (last updated October 04, 2023)
Unbound before 1.4.3 does not properly align structures on 64-bit platforms, which allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.
0