Show filters
33 Total Results
Displaying 11-20 of 33
Sort by:
Attacker Value
Unknown
CVE-2016-3982
Disclosure Date: April 13, 2016 (last updated November 25, 2024)
Off-by-one error in the bmp_rle4_fread function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code via a crafted image file, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2014-0806
Disclosure Date: January 22, 2014 (last updated October 05, 2023)
The Sleipnir Mobile application 2.12.1 and earlier and Sleipnir Mobile Black Edition application 2.12.1 and earlier for Android provide Geolocation API data without verifying user consent, which allows remote attackers to obtain sensitive location information via a web site that makes API calls.
0
Attacker Value
Unknown
CVE-2013-2317
Disclosure Date: June 03, 2013 (last updated October 05, 2023)
The Sleipnir Mobile application 2.9.1 and earlier and Sleipnir Mobile Black Edition application 2.9.1 and earlier for Android allow remote attackers to spoof the address bar via vectors involving the opening of a new window.
0
Attacker Value
Unknown
CVE-2013-3496
Disclosure Date: May 22, 2013 (last updated October 05, 2023)
Infotecs ViPNet Client 3.2.10 (15632) and earlier, ViPNet Coordinator 3.2.10 (15632) and earlier, ViPNet Personal Firewall 3.1 and earlier, and ViPNet SafeDisk 4.1 (0.5643) and earlier use weak permissions (Everyone: Full Control) for a folder under %PROGRAMFILES%\Infotecs, which allows local users to gain privileges via a Trojan horse (1) executable file or (2) DLL file.
0
Attacker Value
Unknown
CVE-2013-2304
Disclosure Date: April 16, 2013 (last updated October 05, 2023)
The Sleipnir Mobile application 2.8.0 and earlier and Sleipnir Mobile Black Edition application 2.8.0 and earlier for Android allow remote attackers to load arbitrary Extension APIs, and trigger downloads or obtain sensitive HTTP response-body information, via a crafted web page.
0
Attacker Value
Unknown
CVE-2013-2303
Disclosure Date: April 16, 2013 (last updated October 05, 2023)
Sleipnir 4.0.0.4000 and earlier on Windows allows remote attackers to spoof the SSL lock icon and address-bar colors via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-5788
Disclosure Date: November 04, 2012 (last updated October 05, 2023)
The PayPal IPN utility does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function.
0
Attacker Value
Unknown
CVE-2012-4432
Disclosure Date: October 01, 2012 (last updated October 05, 2023)
Use-after-free vulnerability in opngreduc.c in OptiPNG Hg and 0.7.x before 0.7.3 might allow remote attackers to execute arbitrary code via unspecified vectors related to "palette reduction."
0
Attacker Value
Unknown
CVE-2012-4004
Disclosure Date: August 08, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Sleipnir Mobile application 2.2.0 and earlier and Sleipnir Mobile Black Edition application 2.2.0 and earlier for Android allows remote attackers to inject arbitrary web script or HTML via a crafted application that interacts with an unspecified Sleipnir Mobile function.
0
Attacker Value
Unknown
CVE-2012-2649
Disclosure Date: August 08, 2012 (last updated October 04, 2023)
The Sleipnir Mobile application 2.2.0 and earlier and Sleipnir Mobile Black Edition application 2.2.0 and earlier for Android allow remote attackers to execute arbitrary Java methods, and obtain sensitive information or execute arbitrary commands, via a crafted web site.
0