Show filters
84 Total Results
Displaying 21-30 of 84
Sort by:
Attacker Value
Unknown

CVE-2017-7571

Disclosure Date: April 06, 2017 (last updated November 26, 2024)
public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.
Attacker Value
Unknown

CVE-2016-1569

Disclosure Date: January 13, 2016 (last updated November 25, 2024)
FireBird 2.5.5 allows remote authenticated users to cause a denial of service (daemon crash) by using service manager to invoke the gbak utility with an invalid parameter.
0
Attacker Value
Unknown

CVE-2015-4657

Disclosure Date: June 18, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Mailbird 2.0.16.0 and earlier allows remote attackers to inject arbitrary web script or HTML via an e-mail message body with a crafted URL.
0
Attacker Value
Unknown

CVE-2014-9334

Disclosure Date: December 24, 2014 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the Bird Feeder plugin 1.2.3 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) user or (2) password parameter in the bird-feeder page to wp-admin/options-general.php.
0
Attacker Value
Unknown

CVE-2014-9323

Disclosure Date: December 16, 2014 (last updated October 05, 2023)
The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via an op_response action with a non-empty status.
0
Attacker Value
Unknown

CVE-2014-7799

Disclosure Date: October 21, 2014 (last updated October 05, 2023)
The Squishy birds (aka com.tatmob.squishybirds) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-7079

Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Romeo and Juliet (aka jp.co.cybird.appli.android.rjs) application 1.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-5330

Disclosure Date: October 19, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in BirdBlog allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-5841

Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The Girls Calendar Period&Weight (aka jp.co.cybird.apps.lifestyle.cal) application 3.2.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2012-5529

Disclosure Date: November 20, 2012 (last updated October 05, 2023)
TraceManager in Firebird 2.5.0 and 2.5.1, when trace is enabled, allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) by preparing an empty dynamic SQL query.
0