Show filters
664 Total Results
Displaying 221-230 of 664
Sort by:
Attacker Value
Unknown
CVE-2015-7715
Disclosure Date: October 18, 2017 (last updated November 26, 2024)
Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows remote attackers to hijack the authentication of administrators for requests that add a user via an add_user action to administrator/index.php.
0
Attacker Value
Unknown
CVE-2015-7714
Disclosure Date: October 18, 2017 (last updated November 26, 2024)
Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote administrators to execute arbitrary SQL commands via the (1) id, (2) copy_field in a data_copy action, (3) pshow in an update_field action, (4) css, (5) tip, (6) cat_id, (7) text_search, (8) plisting, or (9) pwizard parameter to administrator/index.php.
0
Attacker Value
Unknown
CVE-2017-10862
Disclosure Date: October 12, 2017 (last updated November 26, 2024)
jwt-scala 1.2.2 and earlier fails to verify token signatures correctly which may lead to an attacker being able to pass specially crafted JWT data as a correctly signed token.
0
Attacker Value
Unknown
CVE-2017-13649
Disclosure Date: August 23, 2017 (last updated November 26, 2024)
UnrealIRCd 4.0.13 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command. NOTE: the vendor indicates that there is no common or recommended scenario in which a root script would execute this kill command.
0
Attacker Value
Unknown
CVE-2014-3451
Disclosure Date: August 18, 2017 (last updated November 26, 2024)
OpenFire XMPP Server before 3.10 accepts self-signed certificates, which allows remote attackers to perform unspecified spoofing attacks.
0
Attacker Value
Unknown
CVE-2017-9302
Disclosure Date: May 29, 2017 (last updated November 26, 2024)
RealPlayer 16.0.2.32 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted mp4 file.
0
Attacker Value
Unknown
CVE-2016-7144
Disclosure Date: January 18, 2017 (last updated November 25, 2024)
The m_authenticate function in modules/m_sasl.c in UnrealIRCd before 3.2.10.7 and 4.x before 4.0.6 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.
0
Attacker Value
Unknown
CVE-2016-10027
Disclosure Date: January 12, 2017 (last updated November 08, 2023)
Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.
0
Attacker Value
Unknown
CVE-2016-9018
Disclosure Date: October 28, 2016 (last updated November 25, 2024)
Improper handling of a repeating VRAT chunk in qcpfformat.dll allows attackers to cause a Null pointer dereference and crash in RealNetworks RealPlayer 18.1.5.705 through a crafted .QCP media file.
0
Attacker Value
Unknown
CVE-2015-7707
Disclosure Date: October 05, 2015 (last updated October 05, 2023)
Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-form.jsp.
0