Show filters
30 Total Results
Displaying 21-30 of 30
Sort by:
Attacker Value
Unknown

CVE-2005-0639

Disclosure Date: March 02, 2005 (last updated February 22, 2025)
Multiple vulnerabilities in xli before 1.17 may allow remote attackers to execute arbitrary code via "buffer management errors" from certain image properties, some of which may be related to integer overflows in PPM files.
0
Attacker Value
Unknown

CVE-2005-0638

Disclosure Date: March 02, 2005 (last updated February 22, 2025)
xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly quoted when calling the gunzip command.
0
Attacker Value
Unknown

CVE-2004-2060

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names.
0
Attacker Value
Unknown

CVE-2004-2059

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) SearchFor parameter in [TABLE-NAME]_search.asp, (2) SQL parameter in [TABLE-NAME]_edit.asp, (3) SearchFor parameter in [TABLE]_list.asp, or (4) SQL parameter in export.asp.
0
Attacker Value
Unknown

CVE-2004-2058

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
ASPRunner 2.4 allows remote attackers to gain sensitive information via (1) hidden form fields or (2) error messages.
0
Attacker Value
Unknown

CVE-2004-2057

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
SQL injection vulnerability in ASPRunner 2.4 allows remote attackers to execute arbitrary SQL statements.
0
Attacker Value
Unknown

CVE-2004-0255

Disclosure Date: November 23, 2004 (last updated February 22, 2025)
Xlight 1.52, with log to screen enabled, allows remote attackers to cause a denial of service by requesting a long directory consisting of . (dot) and / (slash) characters, which causes the server to crash when the administrator views the log file, possibly triggering a buffer overflow.
0
Attacker Value
Unknown

CVE-2004-0287

Disclosure Date: November 23, 2004 (last updated February 22, 2025)
Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument containing a large number of / (slash) characters, possibly triggering a buffer overflow.
0
Attacker Value
Unknown

CVE-2001-0775

Disclosure Date: October 18, 2001 (last updated February 22, 2025)
Buffer overflow in xloadimage 4.1 (aka xli 1.16 and 1.17) in Linux allows remote attackers to execute arbitrary code via a FACES format image containing a long (1) Firstname or (2) Lastname field.
0
Attacker Value
Unknown

CVE-1999-1349

Disclosure Date: October 06, 1999 (last updated February 22, 2025)
NFS daemon (nfsd.exe) for Omni-NFS/X 6.1 allows remote attackers to cause a denial of service (resource exhaustion) via certain packets, possibly with the Urgent (URG) flag set, to port 111.
0