Show filters
136 Total Results
Displaying 121-130 of 136
Sort by:
Attacker Value
Unknown
CVE-2009-3602
Disclosure Date: October 13, 2009 (last updated October 04, 2023)
Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to cause secure delegations to be downgraded via DNS spoofing or other DNS-related attacks in conjunction with crafted delegation responses.
0
Attacker Value
Unknown
CVE-2009-1755
Disclosure Date: May 22, 2009 (last updated October 04, 2023)
Off-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query.c in nsd 2.3.7, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger a buffer overflow.
0
Attacker Value
Unknown
CVE-2008-6618
Disclosure Date: April 06, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in ClassSystem 2.3 allow remote attackers to execute arbitrary SQL commands via the teacher_id parameter in (1) class/HomepageMain.php and (2) class/HomepageTop.php, and (3) the message_id parameter in class/MessageReply.php.
0
Attacker Value
Unknown
CVE-2008-6619
Disclosure Date: April 06, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in class/ApplyDB.php in ClassSystem 2.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in class/UploadHomepage/.
0
Attacker Value
Unknown
CVE-2009-1086
Disclosure Date: March 25, 2009 (last updated October 04, 2023)
Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns 1.4.x allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a DNS resource record (RR) with a long (1) class field (clas variable) and possibly (2) TTL field.
0
Attacker Value
Unknown
CVE-2008-4898
Disclosure Date: November 04, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in planetluc RateMe 1.3.3 allows remote attackers to inject arbitrary web script or HTML via the rate parameter in a submit rate action.
0
Attacker Value
Unknown
CVE-2008-4891
Disclosure Date: November 04, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in signme.inc.php in Planetluc SignMe 1.5 before 1.55 allows remote attackers to inject arbitrary web script or HTML via the hash parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2008-4892
Disclosure Date: November 04, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in gallery.inc.php in Planetluc MyGallery 1.7.2 and earlier, and possibly other versions before 1.8.1, allows remote attackers to inject arbitrary web script or HTML via the mghash parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2008-4899
Disclosure Date: November 04, 2008 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in Planetluc RateMe 1.3.3 allows remote attackers to perform unauthorized actions as other users via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-3163
Disclosure Date: July 14, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in dodosmail.php in DodosMail 2.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the dodosmail_header_file parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0