Show filters
136 Total Results
Displaying 121-130 of 136
Sort by:
Attacker Value
Unknown

CVE-2009-3602

Disclosure Date: October 13, 2009 (last updated October 04, 2023)
Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to cause secure delegations to be downgraded via DNS spoofing or other DNS-related attacks in conjunction with crafted delegation responses.
0
Attacker Value
Unknown

CVE-2009-1755

Disclosure Date: May 22, 2009 (last updated October 04, 2023)
Off-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query.c in nsd 2.3.7, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger a buffer overflow.
0
Attacker Value
Unknown

CVE-2008-6618

Disclosure Date: April 06, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in ClassSystem 2.3 allow remote attackers to execute arbitrary SQL commands via the teacher_id parameter in (1) class/HomepageMain.php and (2) class/HomepageTop.php, and (3) the message_id parameter in class/MessageReply.php.
0
Attacker Value
Unknown

CVE-2008-6619

Disclosure Date: April 06, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in class/ApplyDB.php in ClassSystem 2.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in class/UploadHomepage/.
0
Attacker Value
Unknown

CVE-2009-1086

Disclosure Date: March 25, 2009 (last updated October 04, 2023)
Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns 1.4.x allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a DNS resource record (RR) with a long (1) class field (clas variable) and possibly (2) TTL field.
0
Attacker Value
Unknown

CVE-2008-4898

Disclosure Date: November 04, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in planetluc RateMe 1.3.3 allows remote attackers to inject arbitrary web script or HTML via the rate parameter in a submit rate action.
0
Attacker Value
Unknown

CVE-2008-4891

Disclosure Date: November 04, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in signme.inc.php in Planetluc SignMe 1.5 before 1.55 allows remote attackers to inject arbitrary web script or HTML via the hash parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-4892

Disclosure Date: November 04, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in gallery.inc.php in Planetluc MyGallery 1.7.2 and earlier, and possibly other versions before 1.8.1, allows remote attackers to inject arbitrary web script or HTML via the mghash parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-4899

Disclosure Date: November 04, 2008 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in Planetluc RateMe 1.3.3 allows remote attackers to perform unauthorized actions as other users via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-3163

Disclosure Date: July 14, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in dodosmail.php in DodosMail 2.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the dodosmail_header_file parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0