Show filters
30 Total Results
Displaying 21-30 of 30
Sort by:
Attacker Value
Unknown

CVE-2015-1321

Disclosure Date: April 29, 2015 (last updated October 05, 2023)
Use-after-free vulnerability in the file picker implementation in Oxide before 1.6.5 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted webpage.
0
Attacker Value
Unknown

CVE-2015-1317

Disclosure Date: April 08, 2015 (last updated October 05, 2023)
Use-after-free vulnerability in Oxide before 1.5.6 and 1.6.x before 1.6.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by deleting all WebContents while a RenderProcessHost instance still exists.
0
Attacker Value
Unknown

CVE-2014-2016

Disclosure Date: March 25, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in OXID eShop Professional and Community Edition 4.6.8 and earlier, 4.7.x before 4.7.11, and 4.8.x before 4.8.4, and Enterprise Edition 4.6.8 and earlier, 5.0.x before 5.0.11 and 5.1.x before 5.1.4 allow remote attackers to inject arbitrary web script or HTML via the searchtag parameter to the getTag function in (1) application/controllers/details.php or (2) application/controllers/tag.php.
0
Attacker Value
Unknown

CVE-2013-5913

Disclosure Date: October 15, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the getRecommSearch function in recommlist.php in OXID eShop before 4.6.7, Professional and Community Edition 4.7.x before 4.7.8, and Enterprise Edition 5.x before 5.0.8 allows remote attackers to inject arbitrary web script or HTML via the searchrecomm parameter.
0
Attacker Value
Unknown

CVE-2011-4712

Disclosure Date: December 08, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in Oxide WebServer allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in an HTTP request.
0
Attacker Value
Unknown

CVE-2009-3113

Disclosure Date: September 09, 2009 (last updated October 04, 2023)
Unspecified vulnerability in OXID eShop Professional, Enterprise, and Community Edition before 4.1.2, 3.x, and 2.x allows remote attackers to gain write access to product reviews via a crafted parameter.
0
Attacker Value
Unknown

CVE-2009-3112

Disclosure Date: September 09, 2009 (last updated October 04, 2023)
Unspecified vulnerability in OXID eShop Professional, Enterprise, and Community Edition before 4.1.0 allows remote attackers to gain administrator privileges and access the shop backend via a crafted parameter.
0
Attacker Value
Unknown

CVE-2009-2266

Disclosure Date: September 09, 2009 (last updated October 04, 2023)
OXID eShop 4.x before 4.1.4-21266, 3.x, and 2.x allows remote attackers to obtain sensitive information (session details and order history of other users) via a crafted cookie.
0
Attacker Value
Unknown

CVE-2008-5405

Disclosure Date: December 10, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in the RDP protocol password decoder in Cain & Abel 4.9.23 and 4.9.24, and possibly earlier, allows remote attackers to execute arbitrary code via an RDP file containing a long string.
0
Attacker Value
Unknown

CVE-2005-0807

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Multiple buffer overflows in Cain & Abel before 2.67 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via (1) an IKE packet with a large ID field that is not properly handled by the PSK sniffer filter, (2) the HTTP sniffer filter, or the (3) POP3, (4) SMTP, (5) IMAP, (6) NNTP, or (7) TDS sniffer filters.
0