Show filters
64 Total Results
Displaying 31-40 of 64
Sort by:
Attacker Value
Unknown
CVE-2010-1513
Disclosure Date: May 26, 2010 (last updated October 04, 2023)
Multiple integer overflows in src/image.c in Ziproxy before 3.0.1 allow remote attackers to execute arbitrary code via (1) a large JPG image, related to the jpg2bitmap function or (2) a large PNG image, related to the png2bitmap function, leading to heap-based buffer overflows.
0
Attacker Value
Unknown
CVE-2009-4393
Disclosure Date: December 22, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the Document Directorys (danp_documentdirs) extension 1.10.7 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-4391
Disclosure Date: December 22, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the File list (dr_blob) extension 2.1.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2007-5291
Disclosure Date: October 09, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Edit.asp in DB Manager 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
0
Attacker Value
Unknown
CVE-2007-3534
Disclosure Date: July 03, 2007 (last updated October 04, 2023)
SQL injection vulnerability in login.php in WebChat 0.78 allows remote attackers to execute arbitrary SQL commands via the rid parameter.
0
Attacker Value
Unknown
CVE-2007-3153
Disclosure Date: June 11, 2007 (last updated October 04, 2023)
The ares_init:randomize_key function in c-ares, on platforms other than Windows, uses a weak facility for producing a random number sequence (Unix rand), which makes it easier for remote attackers to spoof DNS responses by guessing certain values.
0
Attacker Value
Unknown
CVE-2007-3152
Disclosure Date: June 11, 2007 (last updated October 04, 2023)
c-ares before 1.4.0 uses a predictable seed for the random number generator for the DNS Transaction ID field, which might allow remote attackers to spoof DNS responses by guessing the field value.
0
Attacker Value
Unknown
CVE-2007-1939
Disclosure Date: April 10, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the embedded webserver in Daniel Naber LanguageTool before 0.8.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving an error message, possibly the demultiplex method in HTTPServer.java.
0
Attacker Value
Unknown
CVE-2006-6854
Disclosure Date: December 31, 2006 (last updated October 04, 2023)
The qcamvc_video_init function in qcamvc.c in De Marchi Daniele QuickCam VC Linux device driver (aka quickcam-vc) 1.0.9 and earlier does not properly check a boundary, triggering memory corruption, which might allow attackers to execute arbitrary code via a crafted QuickCam object.
0
Attacker Value
Unknown
CVE-2006-1061
Disclosure Date: March 21, 2006 (last updated February 22, 2025)
Heap-based buffer overflow in cURL and libcURL 7.15.0 through 7.15.2 allows remote attackers to execute arbitrary commands via a TFTP URL (tftp://) with a valid hostname and a long path.
0