Show filters
173 Total Results
Displaying 11-20 of 173
Sort by:
Attacker Value
Unknown

CVE-2013-2100

Disclosure Date: September 29, 2014 (last updated October 05, 2023)
The urlopen function in pym/portage/util/_urlopen.py in Gentoo Portage 2.1.12, when using HTTPS, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and modify binary package lists via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-4909

Disclosure Date: July 29, 2014 (last updated October 05, 2023)
Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted peer message, which triggers an out-of-bounds write.
0
Attacker Value
Unknown

CVE-2013-4223

Disclosure Date: May 23, 2014 (last updated October 05, 2023)
The Gentoo Nullmailer package before 1.11-r2 uses world-readable permissions for /etc/nullmailer/remotes, which allows local users to obtain SMTP authentication credentials by reading the file.
0
Attacker Value
Unknown

CVE-2013-0348

Disclosure Date: December 13, 2013 (last updated October 05, 2023)
thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obtain sensitive information by reading the file.
0
Attacker Value
Unknown

CVE-2013-2031

Disclosure Date: November 18, 2013 (last updated October 05, 2023)
MediaWiki before 1.19.6 and 1.20.x before 1.20.5 allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a CDATA section containing valid UTF-7 encoded sequences in a SVG file, which is then incorrectly interpreted as UTF-8 by Chrome and Firefox.
0
Attacker Value
Unknown

CVE-2013-2032

Disclosure Date: November 18, 2013 (last updated October 05, 2023)
MediaWiki before 1.19.6 and 1.20.x before 1.20.5 does not allow extensions to prevent password changes without using both Special:PasswordReset and Special:ChangePassword, which allows remote attackers to bypass the intended restrictions of an extension that only implements one of these blocks.
0
Attacker Value
Unknown

CVE-2010-1159

Disclosure Date: October 28, 2013 (last updated October 05, 2023)
Multiple heap-based buffer overflows in Aircrack-ng before 1.1 allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a (1) large length value in an EAPOL packet or (2) long EAPOL packet.
0
Attacker Value
Unknown

CVE-2012-4893

Disclosure Date: September 11, 2012 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in file/show.cgi in Webmin 1.590 and earlier allow remote attackers to hijack the authentication of privileged users for requests that (1) read files or execute (2) tar, (3) zip, or (4) gzip commands, a different issue than CVE-2012-2982.
0
Attacker Value
Unknown

CVE-2012-2982

Disclosure Date: September 11, 2012 (last updated October 05, 2023)
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character.
0
Attacker Value
Unknown

CVE-2012-2981

Disclosure Date: September 11, 2012 (last updated October 05, 2023)
Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary Perl code via a crafted file associated with the type (aka monitor type name) parameter.
0