Show filters
150 Total Results
Displaying 111-120 of 150
Sort by:
Attacker Value
Unknown

CVE-2013-2319

Disclosure Date: June 10, 2013 (last updated October 05, 2023)
FileMaker Pro before 12 and Pro Advanced before 12 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2013-1801

Disclosure Date: April 09, 2013 (last updated October 05, 2023)
The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for YAML type conversion, a similar vulnerability to CVE-2013-0156.
0
Attacker Value
Unknown

CVE-2013-1800

Disclosure Date: April 09, 2013 (last updated October 05, 2023)
The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156.
0
Attacker Value
Unknown

CVE-2012-4552

Disclosure Date: November 18, 2012 (last updated October 05, 2023)
Stack-based buffer overflow in the error function in ssg/ssgParser.cxx in PLIB 1.8.5 allows remote attackers to execute arbitrary code via a crafted 3d model file that triggers a long error message, as demonstrated by a .ase file.
0
Attacker Value
Unknown

CVE-2011-4620

Disclosure Date: December 31, 2011 (last updated October 04, 2023)
Buffer overflow in the ulSetError function in util/ulError.cxx in PLIB 1.8.5, as used in TORCS 1.3.1 and other products, allows user-assisted remote attackers to execute arbitrary code via vectors involving a long error message, as demonstrated by a crafted acc file for TORCS. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2011-3817

Disclosure Date: September 24, 2011 (last updated October 04, 2023)
Website Baker 2.8.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/media/parameters.php and certain other files. NOTE: this might overlap CVE-2005-2436.
0
Attacker Value
Unknown

CVE-2011-3385

Disclosure Date: September 02, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in WebsiteBaker before 2.8, as used in LEPTON and possibly other products, allows remote attackers to inject arbitrary web script or HTML via unknown vectors, a different vulnerability than CVE-2006-2307.
0
Attacker Value
Unknown

CVE-2009-2375

Disclosure Date: July 08, 2009 (last updated October 04, 2023)
Stack-based buffer overflow in Photo DVD Maker 8.02, and possibly earlier versions, allows remote attackers to execute arbitrary code via a long File_Name parameter in a .pdm file. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-1257

Disclosure Date: April 07, 2009 (last updated October 04, 2023)
Heap-based buffer overflow in Magic ISO Maker 5.5 build 0274 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted CCD file.
0
Attacker Value
Unknown

CVE-2008-6427

Disclosure Date: March 06, 2009 (last updated October 04, 2023)
SQL injection vulnerability in index.php in Hivemaker Professional 1.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cid parameter.
0