Show filters
267 Total Results
Displaying 241-250 of 267
Sort by:
Attacker Value
Unknown
CVE-2014-3897
Disclosure Date: July 29, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Homepage Decorator PerlMailer 3.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-3452
Disclosure Date: May 16, 2014 (last updated October 05, 2023)
Filters\LAV\avfilter-lav-4.dll in K-lite Codec 10.4.5 and earlier allows remote attackers to cause a denial of service (crash) via a crafted .jpg file.
0
Attacker Value
Unknown
CVE-2014-0349
Disclosure Date: April 12, 2014 (last updated October 05, 2023)
Multiple unspecified vulnerabilities in J2k-Codec allow remote attackers to execute arbitrary code via a crafted JPEG 2000 file.
0
Attacker Value
Unknown
CVE-2013-0899
Disclosure Date: February 23, 2013 (last updated October 05, 2023)
Integer overflow in the padding implementation in the opus_packet_parse_impl function in src/opus_decoder.c in Opus before 1.0.2, as used in Google Chrome before 25.0.1364.97 on Windows and Linux and before 25.0.1364.99 on Mac OS X and other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a long packet.
0
Attacker Value
Unknown
CVE-2011-5200
Disclosure Date: September 23, 2012 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in DeDeCMS, possibly 5.6, allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) list.php, (2) members.php, or (3) book.php.
0
Attacker Value
Unknown
CVE-2011-5189
Disclosure Date: September 20, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Webform Validation module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with permissions to "update Webform nodes" to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-1655
Disclosure Date: September 18, 2012 (last updated October 05, 2023)
Unspecified vulnerability in the UC PayDutchGroup / WeDeal payment module 6.x-1.0 for Drupal allows remote authenticated users to obtain account credentials via unknown attack vectors.
0
Attacker Value
Unknown
CVE-2010-1302
Disclosure Date: April 07, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in dwgraphs.php in the DecryptWeb DW Graphs (com_dwgraphs) component 1.0 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.
0
Attacker Value
Unknown
CVE-2010-1097
Disclosure Date: March 24, 2010 (last updated October 04, 2023)
include/userlogin.class.php in DeDeCMS 5.5 GBK, when session.auto_start is enabled, allows remote attackers to bypass authentication and gain administrative access via a value of 1 for the _SESSION[dede_admin_id] parameter, as demonstrated by a request to uploads/include/dialog/select_soft_post.php.
0
Attacker Value
Unknown
CVE-2010-0710
Disclosure Date: February 25, 2010 (last updated October 04, 2023)
SQL injection vulnerability in default.asp in ASPCode CMS 1.5.8, 2.0.0 Build 103, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the newsid parameter when the sec parameter is 26. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0