Show filters
301 Total Results
Displaying 201-210 of 301
Sort by:
Attacker Value
Unknown
CVE-2012-6626
Disclosure Date: January 16, 2014 (last updated October 05, 2023)
SQL injection vulnerability in verify-user.php in b2ePMS 1.0 allows remote attackers to execute arbitrary SQL commands via the username field.
0
Attacker Value
Unknown
CVE-2013-5372
Disclosure Date: October 19, 2013 (last updated October 05, 2023)
The XML4J parser in IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.7, and 8.0 before 8.0.0.4 and IBM Integration Bus 9.0 before 9.0.0.1 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document that triggers expansion for many entities.
0
Attacker Value
Unknown
CVE-2013-4653
Disclosure Date: August 20, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the signin functionality of ics in MyTeamwork services in Alcatel-Lucent Omnitouch 8660 My Teamwork before 6.7, Omnitouch 8670 Automated Message Delivery System (AMDS) before 6.7, Omnitouch 8460 Advanced Communication Server before 9.1, and OmniTouch 8400 Instant Communications Suite before 6.7.3 (1) allow remote attackers to inject arbitrary web script or HTML via a crafted URL that results in a reflected XSS or (2) allow user-assisted remote attackers to inject arbitrary web script or HTML via a user's personal bookmark entry that results in a stored XSS via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-3480
Disclosure Date: August 09, 2013 (last updated October 05, 2023)
Integer overflow in Sagelight 4.4 and earlier allows remote attackers to execute arbitrary code via crafted width and height dimensions in a BMP file, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2013-3659
Disclosure Date: August 09, 2013 (last updated October 05, 2023)
The NTT DOCOMO overseas usage application 2.0.0 through 2.0.4 for Android does not properly connect to Wi-Fi access points, which allows remote attackers to obtain sensitive information by leveraging presence in an 802.11 network's coverage area.
0
Attacker Value
Unknown
CVE-2013-0482
Disclosure Date: May 29, 2013 (last updated October 05, 2023)
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 through 8.5.0.2 and WebSphere Message Broker 6.1, 7.0 through 7.0.0.5, and 8.0 through 8.0.0.2, when WS-Security is used, allows remote attackers to spoof the signatures of messages via a crafted SOAP message, related to a "Signature Wrap attack," a different vulnerability than CVE-2011-1377 and CVE-2013-0489.
0
Attacker Value
Unknown
CVE-2012-6273
Disclosure Date: February 24, 2013 (last updated October 05, 2023)
SQL injection vulnerability in BigAntSoft BigAnt IM Message Server allows remote attackers to execute arbitrary SQL commands via an SHU (aka search user) request.
0
Attacker Value
Unknown
CVE-2012-6274
Disclosure Date: February 24, 2013 (last updated October 05, 2023)
BigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to create arbitrary files under AntServer\DocData\Public via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-6275
Disclosure Date: February 24, 2013 (last updated October 05, 2023)
Multiple stack-based buffer overflows in AntDS.exe in BigAntSoft BigAnt IM Message Server allow remote attackers to have an unspecified impact via (1) the filename header in an SCH request or (2) the userid component in a DUPF request.
0
Attacker Value
Unknown
CVE-2013-0466
Disclosure Date: February 20, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in IBM WebSphere Message Broker 7.0 before 7.0.0.6 and 8.0 before 8.0.0.2, when wsdl support is enabled on a SOAPInput node, allows remote attackers to inject arbitrary web script or HTML via a wsdl request that is not properly handled during construction of an error message.
0