Show filters
77 Total Results
Displaying 21-30 of 77
Sort by:
Attacker Value
Unknown

CVE-2014-9919

Disclosure Date: May 15, 2019 (last updated November 27, 2024)
An issue was discovered in Bilboplanet 2.0. Stored XSS exists in the fullname parameter to signup.php.
0
Attacker Value
Unknown

CVE-2014-9918

Disclosure Date: May 15, 2019 (last updated November 27, 2024)
An issue was discovered in Bilboplanet 2.0. Stored XSS exists in the user_id parameter to signup.php.
0
Attacker Value
Unknown

CVE-2014-9917

Disclosure Date: May 15, 2019 (last updated November 27, 2024)
An issue was discovered in Bilboplanet 2.0. There is a stored XSS vulnerability when adding a tag via the user/?page=tribes tags parameter.
0
Attacker Value
Unknown

CVE-2017-10055

Disclosure Date: October 19, 2017 (last updated November 26, 2024)
Vulnerability in the Oracle iPlanet Web Server component of Oracle Fusion Middleware (subcomponent: Admin Graphical User Interface). The supported version that is affected is 7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iPlanet Web Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iPlanet Web Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle iPlanet Web Server accessible data as well as unauthorized read access to a subset of Oracle iPlanet Web Server accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
0
Attacker Value
Unknown

CVE-2014-9916

Disclosure Date: February 24, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in Bilboplanet 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) tribe_name or (2) tags parameter in a tribes page request to user/ or the (3) user_id or (4) fullname parameter to signup.php.
Attacker Value
Unknown

CVE-2016-1950

Disclosure Date: March 13, 2016 (last updated October 23, 2024)
Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate.
0
Attacker Value
Unknown

CVE-2015-7182

Disclosure Date: November 05, 2015 (last updated October 23, 2024)
Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data.
0
Attacker Value
Unknown

CVE-2014-7478

Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The nashaplaneta.su (aka com.wNashaPlaneta) application 1.02 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-7463

Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The IM5 Fans Planet (aka uk.co.pixelkicks.im5) application 2.3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-7035

Disclosure Date: October 16, 2014 (last updated October 05, 2023)
The Harmonizers Planet (aka uk.co.pixelkicks.fifthharmony) application 2.3.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0