Show filters
46 Total Results
Displaying 21-30 of 46
Sort by:
Attacker Value
Unknown

CVE-2015-9432

Disclosure Date: September 26, 2019 (last updated November 27, 2024)
The alpine-photo-tile-for-instagram plugin before 1.2.7.6 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=alpine-photo-tile-for-instagram-settings tab parameter.
Attacker Value
Unknown

CVE-2018-1000849

Disclosure Date: December 20, 2018 (last updated November 27, 2024)
Alpine Linux version Versions prior to 2.6.10, 2.7.6, and 2.10.1 contains a Other/Unknown vulnerability in apk-tools (Alpine Linux' package manager) that can result in Remote Code Execution. This attack appear to be exploitable via A specially crafted APK-file can cause apk to write arbitrary data to an attacker-specified file, due to bugs in handling long link target name and the way a regular file is extracted.. This vulnerability appears to have been fixed in 2.6.10, 2.7.6, and 2.10.1.
0
Attacker Value
Unknown

CVE-2017-9669

Disclosure Date: July 17, 2017 (last updated November 26, 2024)
A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achieve code execution by crafting a malicious APKINDEX.tar.gz file.
0
Attacker Value
Unknown

CVE-2017-9671

Disclosure Date: July 17, 2017 (last updated November 26, 2024)
A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achieve code execution, by crafting a malicious APKINDEX.tar.gz file with a bad pax header block.
0
Attacker Value
Unknown

CVE-2015-4624

Disclosure Date: March 31, 2017 (last updated November 26, 2024)
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
0
Attacker Value
Unknown

CVE-2008-5005

Disclosure Date: November 10, 2008 (last updated October 04, 2023)
Multiple stack-based buffer overflows in (1) University of Washington IMAP Toolkit 2002 through 2007c, (2) University of Washington Alpine 2.00 and earlier, and (3) Panda IMAP allow (a) local users to gain privileges by specifying a long folder extension argument on the command line to the tmail or dmail program; and (b) remote attackers to execute arbitrary code by sending e-mail to a destination mailbox name composed of a username and '+' character followed by a long string, processed by the tmail or possibly dmail program.
0
Attacker Value
Unknown

CVE-2007-0101

Disclosure Date: January 08, 2007 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in SPINE allows remote attackers to perform unauthorized actions as administrators via unspecified vectors. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2006-6894

Disclosure Date: December 31, 2006 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in SPINE before 1.2 have unknown impact and attack vectors, related to (1) "Placeholders in database handler" and (2) "Macro admin security."
0
Attacker Value
Unknown

CVE-2006-0071

Disclosure Date: January 04, 2006 (last updated February 22, 2025)
The ebuild for pinentry before 0.7.2-r2 on Gentoo Linux sets setgid bits for pinentry programs, which allows local users to read or overwrite arbitrary files as gid 0.
0
Attacker Value
Unknown

CVE-2005-1066

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Race condition in rpdump in Pine 4.62 and earlier allows local users to overwrite arbitrary files via a symlink attack.
0