Show filters
51 Total Results
Displaying 31-40 of 51
Sort by:
Attacker Value
Unknown

CVE-2019-16139

Disclosure Date: September 09, 2019 (last updated November 27, 2024)
An issue was discovered in the compact_arena crate before 0.4.0 for Rust. Generativity is mishandled, leading to an out-of-bounds write or read.
Attacker Value
Unknown

CVE-2019-15567

Disclosure Date: August 26, 2019 (last updated November 27, 2024)
OpenForis Arena before 2019-05-07 allows SQL injection in the sorting feature.
0
Attacker Value
Unknown

CVE-2019-13510

Disclosure Date: August 15, 2019 (last updated December 21, 2024)
Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain a USE AFTER FREE CWE-416. A maliciously crafted Arena file opened by an unsuspecting user may result in the application crashing or the execution of arbitrary code.
0
Attacker Value
Unknown

CVE-2019-13511

Disclosure Date: August 15, 2019 (last updated December 21, 2024)
Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain an INFORMATION EXPOSURE CWE-200. A maliciously crafted Arena file opened by an unsuspecting user may result in the limited exposure of information related to the targeted workstation.
Attacker Value
Unknown

CVE-2018-8843

Disclosure Date: May 14, 2018 (last updated November 26, 2024)
Rockwell Automation Arena versions 15.10.00 and prior contains a use after free vulnerability caused by processing specially crafted Arena Simulation Software files that may cause the software application to crash, potentially losing any unsaved data..
0
Attacker Value
Unknown

CVE-2016-1230

Disclosure Date: June 05, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in NTT PC Communications WebARENA Service formmail before 2.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2010-5077

Disclosure Date: October 27, 2014 (last updated October 05, 2023)
server/sv_main.c in Quake3 Arena, as used in ioquake3 before r1762, OpenArena, Tremulous, and other products, allows remote attackers to cause a denial of service (network traffic amplification) via a spoofed (1) getstatus or (2) rcon request.
0
Attacker Value
Unknown

CVE-2014-5815

Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The Solitaire Arena (aka com.mavenhut.solitaire) application 1.0.15 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2011-2764

Disclosure Date: August 04, 2011 (last updated October 04, 2023)
The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not properly determine dangerous file extensions, which allows remote attackers to execute arbitrary code via a crafted third-party addon that creates a Trojan horse DLL file.
0
Attacker Value
Unknown

CVE-2011-1412

Disclosure Date: August 04, 2011 (last updated October 04, 2023)
sys/sys_unix.c in the ioQuake3 engine on Unix and Linux, as used in World of Padman 1.5.x before 1.5.1.1 and OpenArena 0.8.x-15 and 0.8.x-16, allows remote game servers to execute arbitrary commands via shell metacharacters in a long fs_game variable.
0