Show filters
501 Total Results
Displaying 411-420 of 501
Sort by:
Attacker Value
Unknown

CVE-2009-2625

Disclosure Date: August 06, 2009 (last updated October 04, 2023)
XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
0
Attacker Value
Unknown

CVE-2009-2100

Disclosure Date: June 17, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in the JoomlaPraise Projectfork (com_projectfork) component 2.0.10 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the section parameter to index.php.
0
Attacker Value
Unknown

CVE-2009-1627

Disclosure Date: May 12, 2009 (last updated October 04, 2023)
Stack-based buffer overflow in Streaming Download Project (SDP) Downloader 2.3.0 allows remote attackers to execute arbitrary code via a long .asf URL in the HREF attribute of a REF element in a .asx file.
0
Attacker Value
Unknown

CVE-2009-1500

Disclosure Date: May 01, 2009 (last updated October 04, 2023)
SQL injection vulnerability in index.php in ProjectCMS 1.0 Beta allows remote attackers to execute arbitrary SQL commands via the sn parameter.
0
Attacker Value
Unknown

CVE-2008-6747

Disclosure Date: April 23, 2009 (last updated October 04, 2023)
dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain privileges. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-6552

Disclosure Date: March 30, 2009 (last updated October 04, 2023)
Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9.
0
Attacker Value
Unknown

CVE-2008-6274

Disclosure Date: February 25, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in index.php in FamilyProject 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the logmbr parameter (aka login field) or (2) the mdpmbr parameter (aka pass or "Mot de passe" field). NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-0407

Disclosure Date: February 03, 2009 (last updated October 04, 2023)
SQL injection vulnerability in admin/login.php in PHP-CMS Project 1 allows remote attackers to execute arbitrary SQL commands via the username parameter.
0
Attacker Value
Unknown

CVE-2009-0280

Disclosure Date: January 27, 2009 (last updated October 04, 2023)
Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the crypt cookie to 1.
0
Attacker Value
Unknown

CVE-2008-5584

Disclosure Date: December 15, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ProjectPier 0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) a message, (2) a milestone, or (3) a display name in a profile, or the (4) a or (5) c parameter to index.php.
0