Show filters
321 Total Results
Displaying 231-240 of 321
Sort by:
Attacker Value
Unknown
CVE-2013-1461
Disclosure Date: January 31, 2013 (last updated October 05, 2023)
The ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to cause a denial of service (NULL pointer dereference and service crash) via a SOAPAction header that lacks a # (pound sign) character, a different vulnerability than CVE-2013-0230.
0
Attacker Value
Unknown
CVE-2012-4471
Disclosure Date: November 30, 2012 (last updated October 05, 2023)
The Search Autocomplete module 7.x-2.x before 7.x-2.4 for Drupal does not properly restrict access to the module admin page, which allows remote attackers to disable an autocompletion or change the priority order via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-1638
Disclosure Date: September 19, 2012 (last updated October 05, 2023)
SQL injection vulnerability in the Search Autocomplete module before 7.x-2.1 for Drupal allows remote authenticated users with the "use search_autocomplete" permission to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2010-5081
Disclosure Date: December 25, 2011 (last updated October 04, 2023)
Stack-based buffer overflow in Mini-Stream RM-MP3 Converter 3.1.2.1 allows remote attackers to execute arbitrary code via a long URL in a .pls file.
0
Attacker Value
Unknown
CVE-2009-5109
Disclosure Date: December 25, 2011 (last updated October 04, 2023)
Stack-based buffer overflow in Mini-Stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long entry in a .pls file.
0
Attacker Value
Unknown
CVE-2010-4977
Disclosure Date: November 01, 2011 (last updated October 04, 2023)
SQL injection vulnerability in menu.php in the Canteen (com_canteen) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the mealid parameter to index.php.
0
Attacker Value
Unknown
CVE-2011-3861
Disclosure Date: September 28, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Web Minimalist 200901 theme before 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.
0
Attacker Value
Unknown
CVE-2009-4761
Disclosure Date: March 29, 2010 (last updated October 04, 2023)
Stack-based buffer overflow in Mini-stream RM Downloader allows remote attackers to execute arbitrary code via a long string in a .smi file.
0
Attacker Value
Unknown
CVE-2009-4343
Disclosure Date: December 17, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Training Company Database (trainincdb) extension 0.4.7 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-6933
Disclosure Date: August 11, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in MiniGal b13 (aka MG2) allows remote attackers to read the source code of .php files, and possibly the content of other files, via a .. (dot dot) in the list parameter.
0