Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown

CVE-2021-44538

Disclosure Date: December 14, 2021 (last updated February 23, 2025)
The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is partially controllable by the remote party of the channel. Attackers can construct a crafted sequence of messages to manipulate the state of the receiver's session in such a way that, for some buffer sizes, a buffer overflow happens on a call to olm_session_describe. Furthermore, safe buffer sizes were undocumented. The overflow content is partially controllable by the attacker and limited to ASCII spaces and digits. The known affected products are Element Web And SchildiChat Web.
Attacker Value
Unknown

CVE-2020-23983

Disclosure Date: August 27, 2020 (last updated February 22, 2025)
Michael-design iChat Realtime PHP Live Support System 1.6 has persistent Cross-site Scripting via chat,text-filed tags.
Attacker Value
Unknown

CVE-2015-6512

Disclosure Date: August 18, 2015 (last updated October 05, 2023)
SQL injection vulnerability in the get_messages function in server/plugins/chatroom/chatroom.php in FreiChat 9.6 allows remote attackers to execute arbitrary SQL commands via the time parameter to server/freichat.php.
0
Attacker Value
Unknown

CVE-2013-5952

Disclosure Date: March 19, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Freichat (com_freichat) component, possibly 9.4 and earlier, for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) id or (2) xhash parameter to client/chat.php or (3) toname parameter to client/plugins/upload/upload.php.
0
Attacker Value
Unknown

CVE-2012-4672

Disclosure Date: August 25, 2012 (last updated October 04, 2023)
Apple iChat Server does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via responses for domains that were not asserted.
0
Attacker Value
Unknown

CVE-2010-4949

Disclosure Date: October 09, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the (1) FreiChat component before 2.1.2 for Joomla! and the (2) FreiChatPure component before 1.2.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML by entering it in an unspecified window.
0
Attacker Value
Unknown

CVE-2007-3746

Disclosure Date: August 03, 2007 (last updated October 04, 2023)
The Java interface to CoreAudio on Apple Mac OS X 10.3.9 and 10.4.10 does not properly check the bounds of heap read and write operations, which allows remote attackers to execute arbitrary code via a crafted applet.
0
Attacker Value
Unknown

CVE-2007-3748

Disclosure Date: August 03, 2007 (last updated October 04, 2023)
Buffer overflow in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) implementation in iChat on Apple Mac OS X 10.3.9 and 10.4.10 allows network-adjacent remote attackers to execute arbitrary code via a crafted packet.
0
Attacker Value
Unknown

CVE-2007-3747

Disclosure Date: August 03, 2007 (last updated October 04, 2023)
The Java interface to CoreAudio on Apple Mac OS X 10.3.9 and 10.4.10 does not restrict object instantiation and manipulation to valid heap addresses, which allows remote attackers to execute arbitrary code via a crafted applet.
0
Attacker Value
Unknown

CVE-2007-0710

Disclosure Date: February 16, 2007 (last updated October 04, 2023)
The Bonjour functionality in iChat in Apple Mac OS X 10.3.9 allows remote attackers to cause a denial of service (persistent application crash) via unspecified vectors, possibly related to CVE-2007-0614.
0