Show filters
20 Total Results
Displaying 11-20 of 20
Sort by:
Attacker Value
Unknown

CVE-2005-2971

Disclosure Date: October 20, 2005 (last updated February 22, 2025)
Heap-based buffer overflow in the KWord RTF importer for KOffice 1.2.0 through 1.4.1 allows remote attackers to execute arbitrary code via a crafted RTF file.
0
Attacker Value
Unknown

CVE-2005-0302

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
SQL injection vulnerability in default.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to execute arbitrary SQL commands via the referer field in the HTTP header.
0
Attacker Value
Unknown

CVE-2005-0303

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_supportError.asp or (2) comersus_backofficelite_supportError.asp in BackOffice Lite 6.0 and 6.01 allow remote attackers to inject arbitrary web script or HTML via the error parameter.
0
Attacker Value
Unknown

CVE-2005-0301

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
comersus_backoffice_install10.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to bypass authentication and gain privileges via a direct request to the program.
0
Attacker Value
Unknown

CVE-2005-0206

Disclosure Date: April 27, 2005 (last updated February 22, 2025)
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
0
Attacker Value
Unknown

CVE-2004-0888

Disclosure Date: January 27, 2005 (last updated February 22, 2025)
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
0
Attacker Value
Unknown

CVE-2004-0889

Disclosure Date: January 27, 2005 (last updated February 22, 2025)
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.
0
Attacker Value
Unknown

CVE-2002-0736

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
Microsoft BackOffice 4.0 and 4.5, when configured to be accessible by other systems, allows remote attackers to bypass authentication and access the administrative ASP pages via an HTTP request with an authorization type (auth_type) that is not blank.
0
Attacker Value
Unknown

CVE-1999-0379

Disclosure Date: February 22, 1999 (last updated February 22, 2025)
Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting.
0
Attacker Value
Unknown

CVE-1999-0372

Disclosure Date: February 12, 1999 (last updated February 22, 2025)
The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.
0