Show filters
301 Total Results
Displaying 201-210 of 301
Sort by:
Attacker Value
Unknown

CVE-2012-6626

Disclosure Date: January 16, 2014 (last updated October 05, 2023)
SQL injection vulnerability in verify-user.php in b2ePMS 1.0 allows remote attackers to execute arbitrary SQL commands via the username field.
0
Attacker Value
Unknown

CVE-2013-5372

Disclosure Date: October 19, 2013 (last updated October 05, 2023)
The XML4J parser in IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.7, and 8.0 before 8.0.0.4 and IBM Integration Bus 9.0 before 9.0.0.1 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document that triggers expansion for many entities.
0
Attacker Value
Unknown

CVE-2013-4653

Disclosure Date: August 20, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the signin functionality of ics in MyTeamwork services in Alcatel-Lucent Omnitouch 8660 My Teamwork before 6.7, Omnitouch 8670 Automated Message Delivery System (AMDS) before 6.7, Omnitouch 8460 Advanced Communication Server before 9.1, and OmniTouch 8400 Instant Communications Suite before 6.7.3 (1) allow remote attackers to inject arbitrary web script or HTML via a crafted URL that results in a reflected XSS or (2) allow user-assisted remote attackers to inject arbitrary web script or HTML via a user's personal bookmark entry that results in a stored XSS via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-3480

Disclosure Date: August 09, 2013 (last updated October 05, 2023)
Integer overflow in Sagelight 4.4 and earlier allows remote attackers to execute arbitrary code via crafted width and height dimensions in a BMP file, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2013-3659

Disclosure Date: August 09, 2013 (last updated October 05, 2023)
The NTT DOCOMO overseas usage application 2.0.0 through 2.0.4 for Android does not properly connect to Wi-Fi access points, which allows remote attackers to obtain sensitive information by leveraging presence in an 802.11 network's coverage area.
0
Attacker Value
Unknown

CVE-2013-0482

Disclosure Date: May 29, 2013 (last updated October 05, 2023)
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 through 8.5.0.2 and WebSphere Message Broker 6.1, 7.0 through 7.0.0.5, and 8.0 through 8.0.0.2, when WS-Security is used, allows remote attackers to spoof the signatures of messages via a crafted SOAP message, related to a "Signature Wrap attack," a different vulnerability than CVE-2011-1377 and CVE-2013-0489.
0
Attacker Value
Unknown

CVE-2012-6273

Disclosure Date: February 24, 2013 (last updated October 05, 2023)
SQL injection vulnerability in BigAntSoft BigAnt IM Message Server allows remote attackers to execute arbitrary SQL commands via an SHU (aka search user) request.
0
Attacker Value
Unknown

CVE-2012-6274

Disclosure Date: February 24, 2013 (last updated October 05, 2023)
BigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to create arbitrary files under AntServer\DocData\Public via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-6275

Disclosure Date: February 24, 2013 (last updated October 05, 2023)
Multiple stack-based buffer overflows in AntDS.exe in BigAntSoft BigAnt IM Message Server allow remote attackers to have an unspecified impact via (1) the filename header in an SCH request or (2) the userid component in a DUPF request.
0
Attacker Value
Unknown

CVE-2013-0466

Disclosure Date: February 20, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in IBM WebSphere Message Broker 7.0 before 7.0.0.6 and 8.0 before 8.0.0.2, when wsdl support is enabled on a SOAPInput node, allows remote attackers to inject arbitrary web script or HTML via a wsdl request that is not properly handled during construction of an error message.
0