Show filters
182 Total Results
Displaying 171-180 of 182
Sort by:
Attacker Value
Unknown

CVE-2009-4625

Disclosure Date: January 18, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the updateOnePage function in components/com_bfsurvey_pro/controller.php in BF Survey Pro Free (com_bfsurvey_profree) 1.2.4, and other versions before 1.2.6, a component for Joomla!, allows remote attackers to execute arbitrary SQL commands via the table parameter in an updateOnePage action to index.php.
0
Attacker Value
Unknown

CVE-2008-5429

Disclosure Date: December 11, 2008 (last updated October 04, 2023)
Incredimail build 5853710 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which allows remote attackers to cause a denial of service (stack consumption or other resource consumption) via a large e-mail message, a related issue to CVE-2006-1173.
0
Attacker Value
Unknown

CVE-2007-1683

Disclosure Date: April 26, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in the DoWebMenuAction function in the IncrediMail IMMenuShellExt ActiveX control (ImShExt.dll) allows remote attackers to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown

CVE-2005-4693

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Gaim-Encryption 2.38-1 on Debian Linux allows remote attackers to cause a denial of service (crash) via a crafted message from an ICQ buddy, possibly involving the GE_received_key function in keys.c.
0
Attacker Value
Unknown

CVE-2005-2220

Disclosure Date: July 12, 2005 (last updated February 22, 2025)
Dragonfly Commerce allows remote attackers to change a product price by modifying the x_DragonflyCartProductPrice hidden field to (1) dc_Categorieslist.asp, (2) dc_Categoriesview.asp, (3) dc_productslist.asp, and (4) dc_productslist_Clearance.asp. NOTE: the vendor has disputed this issue, saying that "Dragonfly Commerce does not allow for editing prices nor does it allow for viewing information about clients stored in the database except by the store owner and authorized staff as appointed in the store administration." However, SecurityTracker claims that they have been able to confirm the problem
0
Attacker Value
Unknown

CVE-2005-2221

Disclosure Date: July 12, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in Dragonfly Commerce allows remote attackers to modify SQL statements and possibly execute arbitrary SQL commands via the (1) key parameter to dc_Categoriesview.asp, (2) dc_productslist_Clearance.asp, (3) PID parameter to ratings.asp, (4) dc_Productsview.asp, (5) start, (6) key_mp, (7) searchtype, or (8) psearch parameters to dc_forum_Postslist.asp. NOTE: the vendor has disputed this issue, saying that the error messages arise from invalid category and product numbers. Assuming that this is the case, the issue still satisfies the CVE definition of "exposure.
0
Attacker Value
Unknown

CVE-2003-0163

Disclosure Date: May 05, 2003 (last updated February 22, 2025)
decrypt_msg for the Gaim-Encryption GAIM plugin 1.15 and earlier does not properly validate a message length parameter, which allows remote attackers to cause a denial of service (crash) via a negative length, which overwrites arbitrary heap memory with a zero byte.
0
Attacker Value
Unknown

CVE-2002-0455

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
IncrediMail stores attachments in a directory with a fixed name, which could make it easier for attackers to exploit vulnerabilities in other software that rely on installing and reading files from directories with known pathnames.
0
Attacker Value
Unknown

CVE-2001-0642

Disclosure Date: September 20, 2001 (last updated February 22, 2025)
Directory traversal vulnerability in IncrediMail version 1400185 and earlier allows local users to overwrite files on the local hard drive by appending .. (dot dot) sequences to filenames listed in the content.ini file.
0
Attacker Value
Unknown

CVE-1999-0033

Disclosure Date: June 12, 1997 (last updated February 22, 2025)
Command execution in Sun systems via buffer overflow in the at program.
0