Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2010-4883

Disclosure Date: October 07, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in manager/index.php in MODx Revolution 2.0.2-pl allows remote attackers to inject arbitrary web script or HTML via the modhash parameter.
0
Attacker Value
Unknown

CVE-2009-1631

Disclosure Date: May 14, 2009 (last updated October 04, 2023)
The Mailer component in Evolution 2.26.1 and earlier uses world-readable permissions for the .evolution directory, and certain directories and files under .evolution/ related to local mail, which allows local users to obtain sensitive information by reading these files.
0
Attacker Value
Unknown

CVE-2009-1457

Disclosure Date: April 28, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in player.php in Nuke Evolution Xtreme 2.x allows remote attackers to inject arbitrary web script or HTML via the defaultVisualExt parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2005-2550

Disclosure Date: August 12, 2005 (last updated February 22, 2025)
Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the calendar entries such as task lists, which are not properly handled when the user selects the Calendars tab.
0
Attacker Value
Unknown

CVE-2005-2549

Disclosure Date: August 12, 2005 (last updated February 22, 2025)
Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers.
0
Attacker Value
Unknown

CVE-2005-0806

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Evolution 2.0.3 allows remote attackers to cause a denial of service (application crash or hang) via crafted messages, possibly involving charsets in attachment filenames.
0
Attacker Value
Unknown

CVE-2003-0300

Disclosure Date: June 16, 2003 (last updated February 22, 2025)
The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.
0
Attacker Value
Unknown

CVE-2002-2249

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in News Evolution 2.0 allows remote attackers to execute arbitrary PHP commands via the neurl parameter to (1) backend.php, (2) screen.php, or (3) admin/modules/comment.php.
0