Show filters
247 Total Results
Displaying 221-230 of 247
Sort by:
Attacker Value
Unknown

CVE-2005-1580

Disclosure Date: May 11, 2005 (last updated February 22, 2025)
users.ini.php in BoastMachine 3.0 does not properly restrict the types of files that can be uploaded, which allows remote attackers to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2005-0513

Disclosure Date: February 19, 2005 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in mail_autocheck.php in the Email This Entry add-on for pMachine Pro 2.4, and possibly other versions including pMachine Free, allows remote attackers to execute arbitrary PHP code by directly requesting mail_autocheck.php and modifying the pm_path parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2003-1086.
0
Attacker Value
Unknown

CVE-2004-0723

Disclosure Date: July 27, 2004 (last updated February 22, 2025)
Microsoft Java virtual machine (VM) 5.0.0.3810 allows remote attackers to bypass sandbox restrictions to read or write certain data between applets from different domains via the "GET/Key" and "PUT/Key/Value" commands, aka "cross-site Java."
0
Attacker Value
Unknown

CVE-2004-1853

Disclosure Date: March 19, 2004 (last updated February 22, 2025)
Buffer overflow in Terminator 3: War of the Machines 1.0 allows remote attackers to cause a denial of service via a long ServerInfo variable.
0
Attacker Value
Unknown

CVE-2004-1827

Disclosure Date: March 15, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags.
0
Attacker Value
Unknown

CVE-2003-1086

Disclosure Date: June 17, 2003 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in pm/lib.inc.php in pMachine Free and pMachine Pro 2.2 and 2.2.1 allows remote attackers to execute arbitrary PHP code by modifying the pm_path parameter to reference a URL on a remote web server that contains the code.
0
Attacker Value
Unknown

CVE-2003-0111

Disclosure Date: May 05, 2003 (last updated February 22, 2025)
The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka "Flaw in Microsoft VM Could Enable System Compromise."
0
Attacker Value
Unknown

CVE-2002-1292

Disclosure Date: November 29, 2002 (last updated February 22, 2025)
The Microsoft Java virtual machine (VM) build 5.0.3805 and earlier, as used in Internet Explorer, allows remote attackers to extend the Standard Security Manager (SSM) class (com.ms.security.StandardSecurityManager) and bypass intended StandardSecurityManager restrictions by modifying the (1) deniedDefinitionPackages or (2) deniedAccessPackages settings, causing a denial of service by adding Java applets to the list of applets that are prevented from running.
0
Attacker Value
Unknown

CVE-2002-1294

Disclosure Date: November 29, 2002 (last updated February 22, 2025)
The Microsoft Java implementation, as used in Internet Explorer, can provide HTML object references to applets via Javascript, which allows remote attackers to cause a denial of service (crash due to illegal memory accesses) and possibly conduct other unauthorized activities via an applet that uses those references to access proprietary Microsoft methods.
0
Attacker Value
Unknown

CVE-2002-1286

Disclosure Date: November 29, 2002 (last updated February 22, 2025)
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to steal cookies and execute script in a different security context via a URL that contains a colon in the domain portion, which is not properly parsed and loads an applet from a malicious site within the security context of the site that is being visited by the user.
0