Show filters
64 Total Results
Displaying 31-40 of 64
Sort by:
Attacker Value
Unknown

CVE-2010-1513

Disclosure Date: May 26, 2010 (last updated October 04, 2023)
Multiple integer overflows in src/image.c in Ziproxy before 3.0.1 allow remote attackers to execute arbitrary code via (1) a large JPG image, related to the jpg2bitmap function or (2) a large PNG image, related to the png2bitmap function, leading to heap-based buffer overflows.
0
Attacker Value
Unknown

CVE-2009-4393

Disclosure Date: December 22, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the Document Directorys (danp_documentdirs) extension 1.10.7 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2009-4391

Disclosure Date: December 22, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the File list (dr_blob) extension 2.1.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2007-5291

Disclosure Date: October 09, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Edit.asp in DB Manager 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
0
Attacker Value
Unknown

CVE-2007-3534

Disclosure Date: July 03, 2007 (last updated October 04, 2023)
SQL injection vulnerability in login.php in WebChat 0.78 allows remote attackers to execute arbitrary SQL commands via the rid parameter.
0
Attacker Value
Unknown

CVE-2007-3153

Disclosure Date: June 11, 2007 (last updated October 04, 2023)
The ares_init:randomize_key function in c-ares, on platforms other than Windows, uses a weak facility for producing a random number sequence (Unix rand), which makes it easier for remote attackers to spoof DNS responses by guessing certain values.
0
Attacker Value
Unknown

CVE-2007-3152

Disclosure Date: June 11, 2007 (last updated October 04, 2023)
c-ares before 1.4.0 uses a predictable seed for the random number generator for the DNS Transaction ID field, which might allow remote attackers to spoof DNS responses by guessing the field value.
0
Attacker Value
Unknown

CVE-2007-1939

Disclosure Date: April 10, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the embedded webserver in Daniel Naber LanguageTool before 0.8.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving an error message, possibly the demultiplex method in HTTPServer.java.
0
Attacker Value
Unknown

CVE-2006-6854

Disclosure Date: December 31, 2006 (last updated October 04, 2023)
The qcamvc_video_init function in qcamvc.c in De Marchi Daniele QuickCam VC Linux device driver (aka quickcam-vc) 1.0.9 and earlier does not properly check a boundary, triggering memory corruption, which might allow attackers to execute arbitrary code via a crafted QuickCam object.
0
Attacker Value
Unknown

CVE-2006-1061

Disclosure Date: March 21, 2006 (last updated February 22, 2025)
Heap-based buffer overflow in cURL and libcURL 7.15.0 through 7.15.2 allows remote attackers to execute arbitrary commands via a TFTP URL (tftp://) with a valid hostname and a long path.
0