Show filters
501 Total Results
Displaying 411-420 of 501
Sort by:
Attacker Value
Unknown
CVE-2009-2625
Disclosure Date: August 06, 2009 (last updated October 04, 2023)
XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
0
Attacker Value
Unknown
CVE-2009-2100
Disclosure Date: June 17, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in the JoomlaPraise Projectfork (com_projectfork) component 2.0.10 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the section parameter to index.php.
0
Attacker Value
Unknown
CVE-2009-1627
Disclosure Date: May 12, 2009 (last updated October 04, 2023)
Stack-based buffer overflow in Streaming Download Project (SDP) Downloader 2.3.0 allows remote attackers to execute arbitrary code via a long .asf URL in the HREF attribute of a REF element in a .asx file.
0
Attacker Value
Unknown
CVE-2009-1500
Disclosure Date: May 01, 2009 (last updated October 04, 2023)
SQL injection vulnerability in index.php in ProjectCMS 1.0 Beta allows remote attackers to execute arbitrary SQL commands via the sn parameter.
0
Attacker Value
Unknown
CVE-2008-6747
Disclosure Date: April 23, 2009 (last updated October 04, 2023)
dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain privileges. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2008-6552
Disclosure Date: March 30, 2009 (last updated October 04, 2023)
Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9.
0
Attacker Value
Unknown
CVE-2008-6274
Disclosure Date: February 25, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in index.php in FamilyProject 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the logmbr parameter (aka login field) or (2) the mdpmbr parameter (aka pass or "Mot de passe" field). NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2009-0407
Disclosure Date: February 03, 2009 (last updated October 04, 2023)
SQL injection vulnerability in admin/login.php in PHP-CMS Project 1 allows remote attackers to execute arbitrary SQL commands via the username parameter.
0
Attacker Value
Unknown
CVE-2009-0280
Disclosure Date: January 27, 2009 (last updated October 04, 2023)
Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the crypt cookie to 1.
0
Attacker Value
Unknown
CVE-2008-5584
Disclosure Date: December 15, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ProjectPier 0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) a message, (2) a milestone, or (3) a display name in a profile, or the (4) a or (5) c parameter to index.php.
0