Show filters
38 Total Results
Displaying 21-30 of 38
Sort by:
Attacker Value
Unknown
CVE-2006-1393
Disclosure Date: March 26, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in the mod_pubcookie Apache application server module in University of Washington Pubcookie 1.x, 3.0.0, 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified attack vectors.
0
Attacker Value
Unknown
CVE-2006-1392
Disclosure Date: March 26, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in the login server in University of Washington Pubcookie 3.0.0, 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified inputs.
0
Attacker Value
Unknown
CVE-2004-2179
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
asycpict.dll, as used in Microsoft products such as Front Page 97 and 98, allows remote attackers to cause a denial of service (hang) via a JPEG image with maximum height and width values.
0
Attacker Value
Unknown
CVE-2004-2538
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Direct static code injection vulnerability in the PCG simple application generation in phpCodeGenie before 3.0.2 allows remote authenticated users to execute arbitrary code via the (1) header or (2) footer.
0
Attacker Value
Unknown
CVE-2004-0867
Disclosure Date: December 23, 2004 (last updated February 22, 2025)
Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session. NOTE: it was later reported that 2.x is also affected.
0
Attacker Value
Unknown
CVE-2004-0866
Disclosure Date: September 16, 2004 (last updated February 22, 2025)
Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.
0
Attacker Value
Unknown
CVE-2003-1275
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Pocket Internet Explorer (PIE) 3.0 allows remote attackers to cause a denial of service (crash) via a Javascript function that uses the object.innerHTML function to recursively call that function.
0
Attacker Value
Unknown
CVE-2002-0153
Disclosure Date: April 22, 2002 (last updated February 22, 2025)
Internet Explorer 5.1 for Macintosh allows remote attackers to bypass security checks and invoke local AppleScripts within a specific HTML element, aka the "Local Applescript Invocation" vulnerability.
0
Attacker Value
Unknown
CVE-2000-1096
Disclosure Date: January 09, 2001 (last updated February 22, 2025)
crontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by the user executing the crontab -e command, which allows local users with write access to the crontab spool directory to execute arbitrary commands by creating world-writeable temporary files and modifying them while the victim is editing the file.
0
Attacker Value
Unknown
CVE-2000-0254
Disclosure Date: April 14, 2000 (last updated February 22, 2025)
The dansie shopping cart application cart.pl allows remote attackers to obtain the shopping cart database and configuration information via a URL that references either the env, db, or vars form variables.
0