Show filters
28 Total Results
Displaying 21-28 of 28
Sort by:
Attacker Value
Unknown

CVE-2019-12736

Disclosure Date: October 02, 2019 (last updated November 27, 2024)
JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection.
Attacker Value
Unknown

CVE-2019-19389

Disclosure Date: August 21, 2019 (last updated November 27, 2024)
JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting.
Attacker Value
Unknown

CVE-2019-10102

Disclosure Date: July 03, 2019 (last updated November 27, 2024)
JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. This issue was fixed in Kotlin plugin version 1.3.30.
0
Attacker Value
Unknown

CVE-2008-5905

Disclosure Date: January 15, 2009 (last updated October 04, 2023)
The web interface plugin in KTorrent before 3.1.4 allows remote attackers to bypass intended access restrictions and upload arbitrary torrent files, and trigger the start of downloads and seeding, via a crafted HTTP POST request.
0
Attacker Value
Unknown

CVE-2008-5906

Disclosure Date: January 15, 2009 (last updated October 04, 2023)
Eval injection vulnerability in the web interface plugin in KTorrent before 3.1.4 allows remote attackers to execute arbitrary PHP code via unspecified parameters to this interface's PHP scripts.
0
Attacker Value
Unknown

CVE-2007-1799

Disclosure Date: April 02, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in torrent.cpp in KTorrent before 2.1.3 only checks for the ".." string, which allows remote attackers to overwrite arbitrary files via modified ".." sequences in a torrent filename, as demonstrated by "../" sequences, due to an incomplete fix for CVE-2007-1384.
0
Attacker Value
Unknown

CVE-2007-1384

Disclosure Date: March 10, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in torrent.cpp in KTorrent before 2.1.2 allows remote attackers to overwrite arbitrary files via ".." sequences in a torrent filename.
0
Attacker Value
Unknown

CVE-2007-1385

Disclosure Date: March 10, 2007 (last updated October 04, 2023)
chunkcounter.cpp in KTorrent before 2.1.2 allows remote attackers to cause a denial of service (crash) and heap corruption via a negative or large idx value.
0