Show filters
321 Total Results
Displaying 201-210 of 321
Sort by:
Attacker Value
Unknown
CVE-2016-4570
Disclosure Date: February 03, 2017 (last updated November 25, 2024)
The mxmlDelete function in mxml-node.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file.
0
Attacker Value
Unknown
CVE-2016-4571
Disclosure Date: February 03, 2017 (last updated November 25, 2024)
The mxml_write_node function in mxml-file.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file.
0
Attacker Value
Unknown
CVE-2016-10173
Disclosure Date: February 01, 2017 (last updated November 25, 2024)
Directory traversal vulnerability in the minitar before 0.6 and archive-tar-minitar 0.5.2 gems for Ruby allows remote attackers to write to arbitrary files via a .. (dot dot) in a TAR archive entry.
0
Attacker Value
Unknown
CVE-2015-6031
Disclosure Date: November 02, 2015 (last updated October 05, 2023)
Buffer overflow in the IGDstartelt function in igd_desc_parse.c in the MiniUPnP client (aka MiniUPnPc) before 1.9.20150917 allows remote UPNP servers to cause a denial of service (application crash) and possibly execute arbitrary code via an "oversized" XML element name.
0
Attacker Value
Unknown
CVE-2015-7226
Disclosure Date: September 17, 2015 (last updated October 05, 2023)
The Administration Views module 7.x-1.x before 7.x-1.5 for Drupal checks access permissions based on the router path from the view instead of the display property, which allows remote attackers to obtain sensitive information via vectors related to the access handler.
0
Attacker Value
Unknown
CVE-2015-6944
Disclosure Date: September 15, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to hijack the authentication of users for requests that execute arbitrary SQL commands via the cmd parameter to sys/sys/listaBD2.jsp.
0
Attacker Value
Unknown
CVE-2015-6945
Disclosure Date: September 15, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to inject arbitrary web script or HTML via the bd parameter to sys/sys/listaBD2.jsp.
0
Attacker Value
Unknown
CVE-2015-5509
Disclosure Date: August 18, 2015 (last updated October 05, 2023)
The Administration Views module 7.x-1.x before 7.x-1.4 for Drupal, when used with other unspecified modules, does not properly grant access to administration pages, which allows remote administrators to bypass intended restrictions via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-5064
Disclosure Date: June 24, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in MySql Lite Administrator (mysql-lite-administrator) beta-1 allow remote attackers to inject arbitrary web script or HTML via the table_name parameter to (1) tabella.php, (2) coloni.php, or (3) insert.php or (4) num_row parameter to coloni.php.
0
Attacker Value
Unknown
CVE-2015-4032
Disclosure Date: May 29, 2015 (last updated October 05, 2023)
projectContents.jsp in the Developer tools in Visual Mining NetCharts Server allows remote attackers to rename arbitrary files, and consequently execute them, via unspecified vectors.
0