Show filters
110 Total Results
Displaying 101-110 of 110
Sort by:
Attacker Value
Unknown
CVE-2010-5214
Disclosure Date: September 06, 2012 (last updated October 05, 2023)
Untrusted search path vulnerability in Fotobook Editor 5.0 2.8.0.1 allows local users to gain privileges via a Trojan horse Fwpuclnt.dll file in the current working directory, as demonstrated by a directory that contains a .dtp file. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2010-3353
Disclosure Date: October 20, 2010 (last updated October 04, 2023)
Cowbell 0.2.7.1 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
0
Attacker Value
Unknown
CVE-2007-4508
Disclosure Date: August 23, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in Rebellion Asura engine, as used for the server in Rogue Trooper 1.0 and earlier and Prism 1.1.1.0 and earlier, allows remote attackers to execute arbitrary code via a long string in a 0xf007 packet for the challenge B query.
0
Attacker Value
Unknown
CVE-2007-4416
Disclosure Date: August 18, 2007 (last updated November 08, 2023)
captcha.php in BellaBook (aka BellaBuffs) allows remote attackers to obtain administrative privileges by sending the admin's username (admin_name) in a pheap_login cookie. NOTE: the vendor disputes this vulnerability because authentication data is derived from the admin_pass and secret variables, in addition to the admin_name; and because the exploit code is designed for an unrelated application
0
Attacker Value
Unknown
CVE-2007-1189
Disclosure Date: March 02, 2007 (last updated October 04, 2023)
Integer overflow in the envwrite function in the Alcatel-Lucent Bell Labs Plan 9 kernel allows local users to overwrite certain memory addresses with kernel memory via a large n argument, as demonstrated by (1) modifying the iseve function to gain privileges and (2) making the devpermcheck function grant unrestricted device permissions.
0
Attacker Value
Unknown
CVE-2006-0675
Disclosure Date: February 13, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in search.php in Siteframe 5.0.1 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
0
Attacker Value
Unknown
CVE-2006-0635
Disclosure Date: February 10, 2006 (last updated February 22, 2025)
Tiny C Compiler (TCC) 0.9.23 (aka TinyCC) evaluates the "i>sizeof(int)" expression to false when i equals -1, which might introduce integer overflow vulnerabilities into applications that could be exploited by context-dependent attackers.
0
Attacker Value
Unknown
CVE-2005-4824
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in web/classes.php in Siteframe before 3.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the LOCAL_PATH parameter, a different vulnerability than CVE-2005-1965.
0
Attacker Value
Unknown
CVE-2005-1965
Disclosure Date: June 16, 2005 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in siteframe.php for Broadpool Siteframe allows remote attackers to execute arbitrary code via a URL in the LOCAL_PATH parameter.
0
Attacker Value
Unknown
CVE-2001-1169
Disclosure Date: September 02, 2001 (last updated February 22, 2025)
keyinit in S/Key does not require authentication to initialize a one-time password sequence, which allows an attacker who has gained privileges to a user account to create new one-time passwords for use in other activities that may use S/Key authentication, such as sudo.
0