Show filters
323 Total Results
Displaying 241-250 of 323
Sort by:
Attacker Value
Unknown

CVE-2014-4881

Disclosure Date: October 16, 2014 (last updated October 05, 2023)
The PartyTrack library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-6860

Disclosure Date: October 02, 2014 (last updated October 05, 2023)
The Trial Tracker (aka com.etcweb.android.trial_tracker) application 1.1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-6833

Disclosure Date: September 30, 2014 (last updated October 05, 2023)
The AuctionTrac Dealer (aka com.adesa.dealer.phone) application 2.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-5179

Disclosure Date: August 06, 2014 (last updated October 05, 2023)
The freelinking module for Drupal, as used in the Freelinking for Case Tracker module, does not properly check access permissions for (1) nodes or (2) users, which allows remote attackers to obtain sensitive information via a crafted link.
0
Attacker Value
Unknown

CVE-2012-6130

Disclosure Date: April 11, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the history display in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via a username, related to generating a link.
0
Attacker Value
Unknown

CVE-2012-6131

Disclosure Date: April 11, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the @action parameter to support/issue1.
0
Attacker Value
Unknown

CVE-2012-6132

Disclosure Date: April 10, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the otk parameter.
0
Attacker Value
Unknown

CVE-2013-0729

Disclosure Date: April 02, 2014 (last updated October 05, 2023)
Heap-based buffer overflow in Tracker Software PDF-XChange before 2.5.208 allows remote attackers to execute arbitrary code via a crafted Define Huffman Table header in a JPEG image file stream in a PDF file.
0
Attacker Value
Unknown

CVE-2013-1953

Disclosure Date: December 09, 2013 (last updated October 05, 2023)
Integer underflow in the input_bmp_reader function in input-bmp.c in AutoTrace 0.31.1 allows context-dependent attackers to have an unspecified impact via a small value in the biSize field in the header of a BMP file, which triggers a buffer overflow.
0
Attacker Value
Unknown

CVE-2012-5324

Disclosure Date: October 08, 2012 (last updated October 05, 2023)
Multiple buffer overflows in the Pdf Printer Preferences ActiveX Control in pdfxctrl.dll in Tracker Software PDF-XChange 3.60.0128 allow remote attackers to execute arbitrary code via a long string in the (1) sub_path parameter to the StoreInRegistry function or (2) sub_key parameter to the InitFromRegistry function.
0