Show filters
31 Total Results
Displaying 21-30 of 31
Sort by:
Attacker Value
Unknown
CVE-2018-6638
Disclosure Date: February 28, 2018 (last updated November 26, 2024)
A stack-based buffer overflow (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. This occurs in a function call in which the first argument is a corrupted offset value and the second argument is a stack buffer. This is fixed in 6.9d.
0
Attacker Value
Unknown
CVE-2018-6639
Disclosure Date: February 28, 2018 (last updated November 26, 2024)
An out-of-bounds write (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. A size used by memmove is read from the input file. This is fixed in 6.9d.
0
Attacker Value
Unknown
CVE-2018-6641
Disclosure Date: February 28, 2018 (last updated November 26, 2024)
An Arbitrary Free (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. Crafted input can overwrite a structure, leading to a function call with an invalid parameter, and a subsequent free of important data such as a function pointer or list pointer. This is fixed in 6.9d.
0
Attacker Value
Unknown
CVE-2017-14507
Disclosure Date: September 29, 2017 (last updated November 26, 2024)
Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) timeline parameter in content_timeline_class.php; or the id parameter to (2) pages/content_timeline_edit.php or (3) pages/content_timeline_index.php.
0
Attacker Value
Unknown
CVE-2007-3874
Disclosure Date: November 06, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in the tftp/mftp daemon in the PXE server component (pxemtftp.exe) in Symantec Altiris Deployment Solution 6.x before 6.8.380.0 allows remote attackers to read arbitrary files via unspecified vectors.
0
Attacker Value
Unknown
CVE-2007-3058
Disclosure Date: June 06, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Madirish Webmail 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[basedir] parameter to (1) calendar.php, (2) compose.php, and (3) index.php, different vectors than CVE-2007-2826. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2007-2826
Disclosure Date: May 22, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in lib/addressbook.php in Madirish Webmail 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[basedir] parameter.
0
Attacker Value
Unknown
CVE-2006-0774
Disclosure Date: February 19, 2006 (last updated February 22, 2025)
SQL injection vulnerability in deleteSession() in DB_eSession library 1.0.2 and earlier, as used in multiple products, allows remote attackers to execute arbitrary SQL commands via the $_sess_id_set variable, which is usually derived from PHPSESSID.
0
Attacker Value
Unknown
CVE-2005-1590
Disclosure Date: May 16, 2005 (last updated February 22, 2025)
The Altiris Client Service for Windows (ACLIENT.EXE) 6.0.88 allows local users to disable password protection and access the administrative interface by finding and showing the "Altiris Client Service" hidden window, disabling the password protection, disabling the "Hide client tray icon box" option, then opening the AClient tray icon and using the View Log File option, a different vulnerability than CVE-2004-2070.
0
Attacker Value
Unknown
CVE-2004-2622
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
AClient.exe in Altiris Deployment Solution 6.x and 5.x does not require authentication from the first Deployment Server that it connects to, which allows remote malicious servers to gain administrator access.
0