Show filters
304 Total Results
Displaying 291-300 of 304
Sort by:
Attacker Value
Unknown
CVE-2007-5085
Disclosure Date: September 26, 2007 (last updated October 04, 2023)
Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "access to Geronimo internals" via unspecified vectors.
0
Attacker Value
Unknown
CVE-2007-4963
Disclosure Date: September 18, 2007 (last updated October 04, 2023)
Visual truncation vulnerability in WinImage 8.10 and earlier allows remote attackers to spoof a destination filename via a long sequence of space characters in a filename within a (1) .IMG or (2) .ISO file. NOTE: this can be leveraged with a separate directory traversal vulnerability to trick a careful user into overwriting arbitrary files.
0
Attacker Value
Unknown
CVE-2007-4964
Disclosure Date: September 18, 2007 (last updated October 04, 2023)
WinImage 8.10 and earlier allows remote attackers to cause a denial of service (infinite loop) via an invalid BPB_BytsPerSec field in the header of a .IMG file.
0
Attacker Value
Unknown
CVE-2007-4962
Disclosure Date: September 18, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in WinImage 8.10 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a .. (dot dot) in a filename within a (1) .IMG or (2) .ISO file. NOTE: this can be leveraged for code execution by writing to a Startup folder.
0
Attacker Value
Unknown
CVE-2007-4548
Disclosure Date: August 27, 2007 (last updated October 04, 2023)
The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administrative access by sending a blank username and password with the command line deployer in the deployment module.
0
Attacker Value
Unknown
CVE-2007-2758
Disclosure Date: May 18, 2007 (last updated October 04, 2023)
Multiple buffer overflows in WinImage 8.0.8000 allow user-assisted remote attackers to execute arbitrary code via a FAT image that contains long directory names in a deeply nested directory structure, which triggers (1) a stack-based buffer overflow during extraction, or (2) a heap-based buffer overflow during traversal.
0
Attacker Value
Unknown
CVE-2007-2315
Disclosure Date: April 26, 2007 (last updated October 04, 2023)
MiniShare 1.5.4, and possibly earlier, allows remote attackers to cause a denial of service (application crash) via a flood of requests for new connections.
0
Attacker Value
Unknown
CVE-2007-0355
Disclosure Date: January 19, 2007 (last updated October 04, 2023)
Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allows local users, and possibly remote attackers, to gain privileges and possibly execute arbitrary code via a registration request with an invalid attr-list field.
0
Attacker Value
Unknown
CVE-2006-6541
Disclosure Date: December 14, 2006 (last updated November 08, 2023)
PHP remote file inclusion vulnerability in signer/final.php in warez distributions of Animated Smiley Generator allows remote attackers to execute arbitrary PHP code via a URL in the smiley parameter. NOTE: the vendor disputes this issue, stating that only Warez versions of Animated Smiley Generator were affected, not the developer-provided software: "Legitimately purchased applications do not allow this exploit.
0
Attacker Value
Unknown
CVE-2006-1944
Disclosure Date: April 20, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in SibSoft CommuniMail 1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the list_id parameter in mailadmin.cgi and (2) the form_id parameter in templates.cgi.
0