Show filters
403 Total Results
Displaying 241-250 of 403
Sort by:
Attacker Value
Unknown

CVE-2011-2747

Disclosure Date: July 28, 2011 (last updated October 04, 2023)
Google Picasa before 3.6 Build 105.67 does not properly handle invalid properties in JPEG images, which allows remote attackers to execute arbitrary code via a crafted image file.
0
Attacker Value
Unknown

CVE-2011-1839

Disclosure Date: April 28, 2011 (last updated October 04, 2023)
IBM Rational Build Forge 7.1.0 uses the HTTP GET method during redirection from the authentication servlet to a PHP script, which makes it easier for context-dependent attackers to discover session IDs by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.
0
Attacker Value
Unknown

CVE-2011-0466

Disclosure Date: April 10, 2011 (last updated October 04, 2023)
The API in SUSE openSUSE Build Service (OBS) 2.0.x before 2.0.8 and 2.1.x before 2.1.6 allows attackers to bypass intended write-access restrictions and modify a (1) package or (2) project via unspecified vectors.
0
Attacker Value
Unknown

CVE-2011-0462

Disclosure Date: April 10, 2011 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the login page in the webui component in SUSE openSUSE Build Service (OBS) before 2.1.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2011-1525

Disclosure Date: April 06, 2011 (last updated October 04, 2023)
Heap-based buffer overflow in rvrender.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.2, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted frame in an Internet Video Recording (IVR) file.
0
Attacker Value
Unknown

CVE-2011-1034

Disclosure Date: February 16, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the UI in IBM Rational Build Forge 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the mod parameter to the fullcontrol program. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2010-4709

Disclosure Date: January 28, 2011 (last updated October 04, 2023)
Heap-based buffer overflow in Automated Solutions Modbus/TCP Master OPC Server before 3.0.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a MODBUS response packet with a crafted length field.
0
Attacker Value
Unknown

CVE-2010-2634

Disclosure Date: August 10, 2010 (last updated October 04, 2023)
RSA enVision before 3.7 SP1 allows remote authenticated users to cause a denial of service via unspecified vectors.
0
Attacker Value
Unknown

CVE-2010-1979

Disclosure Date: May 19, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the Affiliate Datafeeds (com_datafeeds) component build 880 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
0
Attacker Value
Unknown

CVE-2009-4844

Disclosure Date: May 07, 2010 (last updated October 04, 2023)
ToutVirtual VirtualIQ Pro 3.2 build 7882 does not restrict access to the /status URI on port 9080, which allows remote attackers to obtain sensitive Tomcat information via a direct request.
0