Show filters
47 Total Results
Displaying 31-40 of 47
Sort by:
Attacker Value
Unknown
CVE-2009-3785
Disclosure Date: October 26, 2009 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allow remote attackers to hijack the authentication of arbitrary users via unknown vectors.
0
Attacker Value
Unknown
CVE-2008-6935
Disclosure Date: August 11, 2009 (last updated October 04, 2023)
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in an im:// URI.
0
Attacker Value
Unknown
CVE-2009-0585
Disclosure Date: March 14, 2009 (last updated October 04, 2023)
Integer overflow in the soup_base64_encode function in soup-misc.c in libsoup 2.x.x before 2.2.x, and 2.x before 2.24, allows context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation.
0
Attacker Value
Unknown
CVE-2008-2384
Disclosure Date: January 22, 2009 (last updated October 04, 2023)
SQL injection vulnerability in mod_auth_mysql.c in the mod-auth-mysql (aka libapache2-mod-auth-mysql) module for the Apache HTTP Server 2.x, when configured to use a multibyte character set that allows a \ (backslash) as part of the character encoding, allows remote attackers to execute arbitrary SQL commands via unspecified inputs in a login request.
0
Attacker Value
Unknown
CVE-2006-3326
Disclosure Date: June 30, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in QuickZip 3.06.3 allows remote user-assisted attackers to overwrite arbitrary files or directories via .. (dot dot) sequences in filenames within (1) TAR,(2) GZ, and (3) JAR archives. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2006-1744
Disclosure Date: April 12, 2006 (last updated October 04, 2023)
Buffer overflow in pl_main.c in sail in BSDgames before 2.17-7 allows local users to execute arbitrary code via a long player name that is used in a scanf function call.
0
Attacker Value
Unknown
CVE-2004-1837
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Mod_survey 3.0.x before 3.0.16-pre2 and 3.2.x before 3.2.0-pre4 allows remote attackers to inject arbitrary web script or HTML via the certain survey fields or error messages for malformed query strings.
0
Attacker Value
Unknown
CVE-2004-0850
Disclosure Date: December 23, 2004 (last updated February 22, 2025)
Star before 1.5_alpha46 does not drop the effective user ID (euid) before calling external programs, which could allow local users to gain privileges by modifying the RSH environment variable to reference a malicious program.
0
Attacker Value
Unknown
CVE-2004-0259
Disclosure Date: November 23, 2004 (last updated February 22, 2025)
The check_referer() function in Formmail.php 5.0 and earlier allows remote attackers to bypass access restrictions via an empty or spoofed HTTP Referer, as demonstrated using an application on the same web server that contains a cross-site scripting (XSS) issue.
0
Attacker Value
Unknown
CVE-2003-0454
Disclosure Date: August 07, 2003 (last updated February 22, 2025)
Multiple buffer overflows in xgalaga 2.0.34 and earlier allow local users to gain privileges via a long HOME environment variable.
0