Show filters
545 Total Results
Displaying 371-380 of 545
Sort by:
Attacker Value
Unknown
CVE-2017-5831
Disclosure Date: March 03, 2017 (last updated November 26, 2024)
Session fixation vulnerability in the forgot password mechanism in Revive Adserver before 4.0.1, when setting a new password, allows remote attackers to hijack web sessions via the session ID.
0
Attacker Value
Unknown
CVE-2016-9942
Disclosure Date: December 31, 2016 (last updated November 25, 2024)
Heap-based buffer overflow in ultra.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted FramebufferUpdate message with the Ultra type tile, such that the LZO payload decompressed length exceeds what is specified by the tile dimensions.
0
Attacker Value
Unknown
CVE-2016-9941
Disclosure Date: December 31, 2016 (last updated November 25, 2024)
Heap-based buffer overflow in rfbproto.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted FramebufferUpdate message containing a subrectangle outside of the client drawing area.
0
Attacker Value
Unknown
CVE-2016-10072
Disclosure Date: December 27, 2016 (last updated November 08, 2023)
WampServer 3.0.6 has two files called 'wampmanager.exe' and 'unins000.exe' with a weak ACL for Modify. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. To properly exploit this vulnerability, the local attacker must insert an executable file called wampmanager.exe or unins000.exe and replace the original files. The next time one of these programs is launched by a more privileged user, malicious code chosen by the local attacker will run. NOTE: the vendor disputes the relevance of this report, taking the position that a configuration in which "'someone' (an attacker) is able to replace files on a PC" is not "the fault of WampServer.
0
Attacker Value
Unknown
CVE-2016-10031
Disclosure Date: December 27, 2016 (last updated November 08, 2023)
WampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYSTEM privileges. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. To properly exploit this vulnerability, the local attacker must insert an executable file called mysqld.exe or httpd.exe and replace the original files. The next time the service starts, the malicious file will get executed as SYSTEM. NOTE: the vendor disputes the relevance of this report, taking the position that a configuration in which "'someone' (an attacker) is able to replace files on a PC" is not "the fault of WampServer.
0
Attacker Value
Unknown
CVE-2016-1000149
Disclosure Date: October 10, 2016 (last updated November 25, 2024)
Reflected XSS in wordpress plugin simpel-reserveren v3.5.2
0
Attacker Value
Unknown
CVE-2015-7876
Disclosure Date: October 21, 2015 (last updated October 05, 2023)
The escapeLike function in sqlsrv/database.inc in the Drupal 7 driver for SQL Server and SQL Azure 7.x-1.x before 7.x-1.4 does not properly escape certain characters, which allows remote attackers to execute arbitrary SQL commands via vectors involving a module using the db_like function.
0
Attacker Value
Unknown
CVE-2015-7372
Disclosure Date: October 14, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in delivery-dev/al.php in Revive Adserver before 3.2.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the layerstyle parameter.
0
Attacker Value
Unknown
CVE-2015-7365
Disclosure Date: October 14, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the plugin upgrade form in Revive Adserver before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via the filename of an uploaded file containing errors.
0
Attacker Value
Unknown
CVE-2015-7367
Disclosure Date: October 14, 2015 (last updated October 05, 2023)
Revive Adserver before 3.2.2 allows remote attackers to perform unspecified actions by leveraging an unexpired session after the user has been (1) deleted or (2) unlinked.
0