Show filters
321 Total Results
Displaying 221-230 of 321
Sort by:
Attacker Value
Unknown
CVE-2014-5662
Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The Rail Rush (aka com.miniclip.railrush) application 1.9.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-5534
Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The Princess Shopping (aka air.android.PrincessShopping) application 2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-5661
Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The Anger of Stick 3 (aka com.miniclip.angerofstick3) application 1.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2009-5137
Disclosure Date: January 03, 2014 (last updated October 05, 2023)
Stack-based buffer overflow in Mini-stream CastRipper 2.50.70 allows remote attackers to execute arbitrary code via a long URL in the [playlist] section in a .pls file, a different vector than CVE-2009-1667.
0
Attacker Value
Unknown
CVE-2013-6993
Disclosure Date: January 03, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Ad-minister plugin 0.6 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the key parameter in a delete action to wp-admin/tools.php.
0
Attacker Value
Unknown
CVE-2013-2247
Disclosure Date: August 28, 2013 (last updated October 05, 2023)
The Fast Permissions Administration module 6.x-2.x before 6.x-2.5 and 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to the modal content callback, which allows remote attackers to obtain unspecified access to the permissions edit form.
0
Attacker Value
Unknown
CVE-2013-5020
Disclosure Date: July 31, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in bb_admin.php in MiniBB before 3.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) forum_name, (2) forum_group, (3) forum_icon, or (4) forum_desc parameter. NOTE: the whatus vector is already covered by CVE-2008-2066.
0
Attacker Value
Unknown
CVE-2013-0229
Disclosure Date: January 31, 2013 (last updated October 05, 2023)
The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attackers to cause a denial of service (service crash) via a crafted request that triggers a buffer over-read.
0
Attacker Value
Unknown
CVE-2013-0230
Disclosure Date: January 31, 2013 (last updated October 05, 2023)
Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to execute arbitrary code via a long quoted method.
0
Attacker Value
Unknown
CVE-2013-1462
Disclosure Date: January 31, 2013 (last updated October 05, 2023)
Integer signedness error in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to cause a denial of service (incorrect memory copy) via a SOAPAction header that lacks a " (double quote) character, a different vulnerability than CVE-2013-0230.
0