Show filters
45 Total Results
Displaying 21-30 of 45
Sort by:
Attacker Value
Unknown
CVE-2017-5928
Disclosure Date: February 27, 2017 (last updated November 26, 2024)
The W3C High Resolution Time API, as implemented in various web browsers, does not consider that memory-reference times can be measured by a performance.now "Time to Tick" approach even with the https://bugzilla.mozilla.org/show_bug.cgi?id=1167489#c9 protection mechanism in place, which makes it easier for remote attackers to conduct AnC attacks via crafted JavaScript code.
0
Attacker Value
Unknown
CVE-2010-2074
Disclosure Date: June 16, 2010 (last updated October 04, 2023)
istream.c in w3m 0.5.2 and possibly other versions, when ssl_verify_server is enabled, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
0
Attacker Value
Unknown
CVE-2009-2337
Disclosure Date: July 07, 2009 (last updated October 04, 2023)
SQL injection vulnerability in includes/module/book/index.inc.php in w3b|cms Gaestebuch Guestbook Module 3.0.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the spam_id parameter.
0
Attacker Value
Unknown
CVE-2009-1209
Disclosure Date: April 01, 2009 (last updated October 04, 2023)
Stack-based buffer overflow in W3C Amaya Web Browser 11.1 allows remote attackers to execute arbitrary code via a script tag with a long defer attribute.
0
Attacker Value
Unknown
CVE-2008-6385
Disclosure Date: March 02, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in W3matter RevSense 1.0 allows remote attackers to inject arbitrary web script or HTML via the section parameter.
0
Attacker Value
Unknown
CVE-2008-6310
Disclosure Date: February 27, 2009 (last updated October 04, 2023)
SQL injection vulnerability in index.php in W3matter RevSense 1.0 allows remote attackers to execute arbitrary SQL commands via the f[password] parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2008-6309
Disclosure Date: February 27, 2009 (last updated October 04, 2023)
SQL injection vulnerability in index.php in W3matter AskPert allows remote attackers to execute arbitrary SQL commands via the f[password] parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2008-6158
Disclosure Date: February 17, 2009 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in the admin backend in w3b>cms (aka w3blabor CMS) before 3.2.0 have unknown impact and remote attack vectors.
0
Attacker Value
Unknown
CVE-2009-0597
Disclosure Date: February 16, 2009 (last updated October 04, 2023)
SQL injection vulnerability in admin/index.php in w3b>cms (aka w3blabor CMS) before 3.4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the benutzername parameter (aka Username field) in a login action.
0
Attacker Value
Unknown
CVE-2008-6005
Disclosure Date: January 28, 2009 (last updated October 04, 2023)
Multiple buffer overflows in the CheckUniqueName function in W3C Amaya Web Browser 10.0.1, and possibly other versions including 11.0.1, might allow remote attackers to execute arbitrary code via "duplicated" attribute value inputs.
0