Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown

CVE-2007-6360

Disclosure Date: December 15, 2007 (last updated October 04, 2023)
Unspecified vulnerability in the Sun eXtended System Control Facility (XSCF) Control Package (XCP) firmware before 1050 on SPARC Enterprise M4000, M5000, M8000, and M9000 servers allows remote attackers to cause a denial of service (reboot) via (1) telnet, (2) ssh, or (3) http network traffic that triggers memory exhaustion.
0
Attacker Value
Unknown

CVE-2006-3394

Disclosure Date: July 06, 2006 (last updated October 04, 2023)
SQL injection vulnerability in the files mod in index.php in BXCP 0.3.0.4 allows remote attackers to execute arbitrary SQL commands via the where parameter in a view action.
0
Attacker Value
Unknown

CVE-2006-0821

Disclosure Date: February 21, 2006 (last updated February 22, 2025)
SQL injection vulnerability in index.php in BXCP 0.299 allows remote attackers to execute arbitrary SQL commands via the tid parameter.
0
Attacker Value
Unknown

CVE-2005-3650

Disclosure Date: November 17, 2005 (last updated February 22, 2025)
The CodeSupport.ocx ActiveX control, as used by Sony to uninstall the First4Internet XCP DRM, has "safe for scripting" enabled, which allows remote attackers to execute arbitrary code by calling vulnerable functions such as RebootMachine, IsAdministrator, and ExecuteCode.
0
Attacker Value
Unknown

CVE-2005-3474

Disclosure Date: November 03, 2005 (last updated February 22, 2025)
The aries.sys driver in Sony First4Internet XCP DRM software hides any file, registry key, or process with a name that starts with "$sys$", which allows attackers to hide activities on a system that uses XCP.
0