Show filters
45 Total Results
Displaying 21-30 of 45
Sort by:
Attacker Value
Unknown

CVE-2017-5928

Disclosure Date: February 27, 2017 (last updated November 26, 2024)
The W3C High Resolution Time API, as implemented in various web browsers, does not consider that memory-reference times can be measured by a performance.now "Time to Tick" approach even with the https://bugzilla.mozilla.org/show_bug.cgi?id=1167489#c9 protection mechanism in place, which makes it easier for remote attackers to conduct AnC attacks via crafted JavaScript code.
Attacker Value
Unknown

CVE-2010-2074

Disclosure Date: June 16, 2010 (last updated October 04, 2023)
istream.c in w3m 0.5.2 and possibly other versions, when ssl_verify_server is enabled, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
0
Attacker Value
Unknown

CVE-2009-2337

Disclosure Date: July 07, 2009 (last updated October 04, 2023)
SQL injection vulnerability in includes/module/book/index.inc.php in w3b|cms Gaestebuch Guestbook Module 3.0.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the spam_id parameter.
0
Attacker Value
Unknown

CVE-2009-1209

Disclosure Date: April 01, 2009 (last updated October 04, 2023)
Stack-based buffer overflow in W3C Amaya Web Browser 11.1 allows remote attackers to execute arbitrary code via a script tag with a long defer attribute.
0
Attacker Value
Unknown

CVE-2008-6385

Disclosure Date: March 02, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in W3matter RevSense 1.0 allows remote attackers to inject arbitrary web script or HTML via the section parameter.
0
Attacker Value
Unknown

CVE-2008-6310

Disclosure Date: February 27, 2009 (last updated October 04, 2023)
SQL injection vulnerability in index.php in W3matter RevSense 1.0 allows remote attackers to execute arbitrary SQL commands via the f[password] parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-6309

Disclosure Date: February 27, 2009 (last updated October 04, 2023)
SQL injection vulnerability in index.php in W3matter AskPert allows remote attackers to execute arbitrary SQL commands via the f[password] parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-6158

Disclosure Date: February 17, 2009 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in the admin backend in w3b>cms (aka w3blabor CMS) before 3.2.0 have unknown impact and remote attack vectors.
0
Attacker Value
Unknown

CVE-2009-0597

Disclosure Date: February 16, 2009 (last updated October 04, 2023)
SQL injection vulnerability in admin/index.php in w3b>cms (aka w3blabor CMS) before 3.4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the benutzername parameter (aka Username field) in a login action.
0
Attacker Value
Unknown

CVE-2008-6005

Disclosure Date: January 28, 2009 (last updated October 04, 2023)
Multiple buffer overflows in the CheckUniqueName function in W3C Amaya Web Browser 10.0.1, and possibly other versions including 11.0.1, might allow remote attackers to execute arbitrary code via "duplicated" attribute value inputs.
0