Show filters
321 Total Results
Displaying 221-230 of 321
Sort by:
Attacker Value
Unknown

CVE-2014-5662

Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The Rail Rush (aka com.miniclip.railrush) application 1.9.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-5534

Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The Princess Shopping (aka air.android.PrincessShopping) application 2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-5661

Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The Anger of Stick 3 (aka com.miniclip.angerofstick3) application 1.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2009-5137

Disclosure Date: January 03, 2014 (last updated October 05, 2023)
Stack-based buffer overflow in Mini-stream CastRipper 2.50.70 allows remote attackers to execute arbitrary code via a long URL in the [playlist] section in a .pls file, a different vector than CVE-2009-1667.
0
Attacker Value
Unknown

CVE-2013-6993

Disclosure Date: January 03, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Ad-minister plugin 0.6 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the key parameter in a delete action to wp-admin/tools.php.
0
Attacker Value
Unknown

CVE-2013-2247

Disclosure Date: August 28, 2013 (last updated October 05, 2023)
The Fast Permissions Administration module 6.x-2.x before 6.x-2.5 and 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to the modal content callback, which allows remote attackers to obtain unspecified access to the permissions edit form.
0
Attacker Value
Unknown

CVE-2013-5020

Disclosure Date: July 31, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in bb_admin.php in MiniBB before 3.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) forum_name, (2) forum_group, (3) forum_icon, or (4) forum_desc parameter. NOTE: the whatus vector is already covered by CVE-2008-2066.
0
Attacker Value
Unknown

CVE-2013-0229

Disclosure Date: January 31, 2013 (last updated October 05, 2023)
The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attackers to cause a denial of service (service crash) via a crafted request that triggers a buffer over-read.
0
Attacker Value
Unknown

CVE-2013-0230

Disclosure Date: January 31, 2013 (last updated October 05, 2023)
Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to execute arbitrary code via a long quoted method.
0
Attacker Value
Unknown

CVE-2013-1462

Disclosure Date: January 31, 2013 (last updated October 05, 2023)
Integer signedness error in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to cause a denial of service (incorrect memory copy) via a SOAPAction header that lacks a " (double quote) character, a different vulnerability than CVE-2013-0230.
0