Show filters
38 Total Results
Displaying 31-38 of 38
Sort by:
Attacker Value
Unknown
CVE-2009-0803
Disclosure Date: March 04, 2009 (last updated October 04, 2023)
SmoothWall SmoothGuardian, as used in SmoothWall Firewall, NetworkGuardian, and SchoolGuardian 2008, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.
0
Attacker Value
Unknown
CVE-2007-2883
Disclosure Date: May 30, 2007 (last updated October 04, 2023)
Credant Mobile Guardian Shield for Windows 5.2.1.105 and earlier stores account names and passwords in plaintext in memory, which allows local users to obtain sensitive information by (1) reading the paging file or (2) dumping and searching the memory image. NOTE: This issue crosses privilege boundaries because the product is intended to protect the data on a stolen computer.
0
Attacker Value
Unknown
CVE-2004-2282
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
DansGuardian before 2.7.7-2 allows remote attackers to bypass URL filters via a ".." in the request.
0
Attacker Value
Unknown
CVE-2004-2065
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
DansGuardian 2.8 and earlier allows remote attackers to bypass the extension filtering rule via a hex encoded extension or . in the filename.
0
Attacker Value
Unknown
CVE-2004-2283
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Unknown vulnerability in DansGuardian before 2.6.1-13 allows remote attackers to bypass URL filters via a crafted request that causes a page to be added to the clean page cache.
0
Attacker Value
Unknown
CVE-2003-1506
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in dansguardian.pl in Adelix CensorNet 3.0 through 3.2 allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into the DENIEDURL parameter.
0
Attacker Value
Unknown
CVE-2003-0101
Disclosure Date: March 03, 2003 (last updated February 22, 2025)
miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic authentication, which allows remote attackers to spoof a session ID and gain root privileges.
0
Attacker Value
Unknown
CVE-2002-1599
Disclosure Date: July 23, 2002 (last updated February 22, 2025)
DansGuardian before 2.4.5-1 allows remote attackers to bypass content filtering rules via hex-encoded URLs.
0