Show filters
162 Total Results
Displaying 141-150 of 162
Sort by:
Attacker Value
Unknown

CVE-2014-4075

Disclosure Date: October 15, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in System.Web.Mvc.dll in Microsoft ASP.NET Model View Controller (MVC) 2.0 through 5.1 allows remote attackers to inject arbitrary web script or HTML via a crafted web page, aka "MVC XSS Vulnerability."
0
Attacker Value
Unknown

CVE-2014-3038

Disclosure Date: June 08, 2014 (last updated October 05, 2023)
IBM SPSS Modeler 16.0 before 16.0.0.1 on UNIX does not properly drop group privileges, which allows local users to bypass intended file-access restrictions by leveraging (1) gid 0 or (2) root's group memberships.
0
Attacker Value
Unknown

CVE-2012-2328

Disclosure Date: February 10, 2014 (last updated October 05, 2023)
internal/cimxml/sax/NodeFactory.java in Standards-Based Linux Instrumentation for Manageability (SBLIM) Common Information Model (CIM) Client (aka sblim-cim-client2) before 2.1.12 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML file.
0
Attacker Value
Unknown

CVE-2013-6885

Disclosure Date: November 29, 2013 (last updated October 05, 2023)
The microcode on AMD 16h 00h through 0Fh processors does not properly handle the interaction between locked instructions and write-combined memory types, which allows local users to cause a denial of service (system hang) via a crafted application, aka the errata 793 issue.
0
Attacker Value
Unknown

CVE-2012-5769

Disclosure Date: January 01, 2013 (last updated October 05, 2023)
IBM SPSS Modeler 14.0, 14.1, 14.2 through FP3, and 15.0 before FP2 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference.
0
Attacker Value
Unknown

CVE-2010-1705

Disclosure Date: May 04, 2010 (last updated October 04, 2023)
SQL injection vulnerability in casting_view.php in Modelbook allows remote attackers to execute arbitrary SQL commands via the adnum parameter.
0
Attacker Value
Unknown

CVE-2009-4731

Disclosure Date: March 18, 2010 (last updated October 04, 2023)
SQL injection vulnerability in photos.php in Model Agency Manager PRO (formerly Modeling Agency Content Management Script) allows remote attackers to execute arbitrary SQL commands via the album parameter.
0
Attacker Value
Unknown

CVE-2009-3175

Disclosure Date: September 11, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Model Agency Manager PRO (formerly Modeling Agency Content Management Script) allow remote attackers to execute arbitrary SQL commands via the user_id parameter to (1) view.php, (2) photos.php, and (3) motm.php; and the (4) id parameter to forum_message.php.
0
Attacker Value
Unknown

CVE-2008-2674

Disclosure Date: June 12, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the Interstage Management Console, as used in Fujitsu Interstage Application Server 6.0 through 9.0.0A, Apworks Modelers-J 6.0 through 7.0, and Studio 8.0.1 and 9.0.0, allows remote attackers to read or delete arbitrary files via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-2537

Disclosure Date: June 03, 2008 (last updated October 04, 2023)
SQL injection vulnerability in cat.php in HispaH Model Search allows remote attackers to execute arbitrary SQL commands via the cat parameter.
0