Show filters
33 Total Results
Displaying 11-20 of 33
Sort by:
Attacker Value
Unknown

CVE-2016-3982

Disclosure Date: April 13, 2016 (last updated November 25, 2024)
Off-by-one error in the bmp_rle4_fread function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code via a crafted image file, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2014-0806

Disclosure Date: January 22, 2014 (last updated October 05, 2023)
The Sleipnir Mobile application 2.12.1 and earlier and Sleipnir Mobile Black Edition application 2.12.1 and earlier for Android provide Geolocation API data without verifying user consent, which allows remote attackers to obtain sensitive location information via a web site that makes API calls.
0
Attacker Value
Unknown

CVE-2013-2317

Disclosure Date: June 03, 2013 (last updated October 05, 2023)
The Sleipnir Mobile application 2.9.1 and earlier and Sleipnir Mobile Black Edition application 2.9.1 and earlier for Android allow remote attackers to spoof the address bar via vectors involving the opening of a new window.
0
Attacker Value
Unknown

CVE-2013-3496

Disclosure Date: May 22, 2013 (last updated October 05, 2023)
Infotecs ViPNet Client 3.2.10 (15632) and earlier, ViPNet Coordinator 3.2.10 (15632) and earlier, ViPNet Personal Firewall 3.1 and earlier, and ViPNet SafeDisk 4.1 (0.5643) and earlier use weak permissions (Everyone: Full Control) for a folder under %PROGRAMFILES%\Infotecs, which allows local users to gain privileges via a Trojan horse (1) executable file or (2) DLL file.
0
Attacker Value
Unknown

CVE-2013-2304

Disclosure Date: April 16, 2013 (last updated October 05, 2023)
The Sleipnir Mobile application 2.8.0 and earlier and Sleipnir Mobile Black Edition application 2.8.0 and earlier for Android allow remote attackers to load arbitrary Extension APIs, and trigger downloads or obtain sensitive HTTP response-body information, via a crafted web page.
0
Attacker Value
Unknown

CVE-2013-2303

Disclosure Date: April 16, 2013 (last updated October 05, 2023)
Sleipnir 4.0.0.4000 and earlier on Windows allows remote attackers to spoof the SSL lock icon and address-bar colors via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-5788

Disclosure Date: November 04, 2012 (last updated October 05, 2023)
The PayPal IPN utility does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function.
0
Attacker Value
Unknown

CVE-2012-4432

Disclosure Date: October 01, 2012 (last updated October 05, 2023)
Use-after-free vulnerability in opngreduc.c in OptiPNG Hg and 0.7.x before 0.7.3 might allow remote attackers to execute arbitrary code via unspecified vectors related to "palette reduction."
0
Attacker Value
Unknown

CVE-2012-4004

Disclosure Date: August 08, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Sleipnir Mobile application 2.2.0 and earlier and Sleipnir Mobile Black Edition application 2.2.0 and earlier for Android allows remote attackers to inject arbitrary web script or HTML via a crafted application that interacts with an unspecified Sleipnir Mobile function.
0
Attacker Value
Unknown

CVE-2012-2649

Disclosure Date: August 08, 2012 (last updated October 04, 2023)
The Sleipnir Mobile application 2.2.0 and earlier and Sleipnir Mobile Black Edition application 2.2.0 and earlier for Android allow remote attackers to execute arbitrary Java methods, and obtain sensitive information or execute arbitrary commands, via a crafted web site.
0