Show filters
30 Total Results
Displaying 21-30 of 30
Sort by:
Attacker Value
Unknown
CVE-2015-1321
Disclosure Date: April 29, 2015 (last updated October 05, 2023)
Use-after-free vulnerability in the file picker implementation in Oxide before 1.6.5 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted webpage.
0
Attacker Value
Unknown
CVE-2015-1317
Disclosure Date: April 08, 2015 (last updated October 05, 2023)
Use-after-free vulnerability in Oxide before 1.5.6 and 1.6.x before 1.6.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by deleting all WebContents while a RenderProcessHost instance still exists.
0
Attacker Value
Unknown
CVE-2014-2016
Disclosure Date: March 25, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in OXID eShop Professional and Community Edition 4.6.8 and earlier, 4.7.x before 4.7.11, and 4.8.x before 4.8.4, and Enterprise Edition 4.6.8 and earlier, 5.0.x before 5.0.11 and 5.1.x before 5.1.4 allow remote attackers to inject arbitrary web script or HTML via the searchtag parameter to the getTag function in (1) application/controllers/details.php or (2) application/controllers/tag.php.
0
Attacker Value
Unknown
CVE-2013-5913
Disclosure Date: October 15, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the getRecommSearch function in recommlist.php in OXID eShop before 4.6.7, Professional and Community Edition 4.7.x before 4.7.8, and Enterprise Edition 5.x before 5.0.8 allows remote attackers to inject arbitrary web script or HTML via the searchrecomm parameter.
0
Attacker Value
Unknown
CVE-2011-4712
Disclosure Date: December 08, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in Oxide WebServer allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in an HTTP request.
0
Attacker Value
Unknown
CVE-2009-3113
Disclosure Date: September 09, 2009 (last updated October 04, 2023)
Unspecified vulnerability in OXID eShop Professional, Enterprise, and Community Edition before 4.1.2, 3.x, and 2.x allows remote attackers to gain write access to product reviews via a crafted parameter.
0
Attacker Value
Unknown
CVE-2009-3112
Disclosure Date: September 09, 2009 (last updated October 04, 2023)
Unspecified vulnerability in OXID eShop Professional, Enterprise, and Community Edition before 4.1.0 allows remote attackers to gain administrator privileges and access the shop backend via a crafted parameter.
0
Attacker Value
Unknown
CVE-2009-2266
Disclosure Date: September 09, 2009 (last updated October 04, 2023)
OXID eShop 4.x before 4.1.4-21266, 3.x, and 2.x allows remote attackers to obtain sensitive information (session details and order history of other users) via a crafted cookie.
0
Attacker Value
Unknown
CVE-2008-5405
Disclosure Date: December 10, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in the RDP protocol password decoder in Cain & Abel 4.9.23 and 4.9.24, and possibly earlier, allows remote attackers to execute arbitrary code via an RDP file containing a long string.
0
Attacker Value
Unknown
CVE-2005-0807
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Multiple buffer overflows in Cain & Abel before 2.67 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via (1) an IKE packet with a large ID field that is not properly handled by the PSK sniffer filter, (2) the HTTP sniffer filter, or the (3) POP3, (4) SMTP, (5) IMAP, (6) NNTP, or (7) TDS sniffer filters.
0