Show filters
52 Total Results
Displaying 41-50 of 52
Sort by:
Attacker Value
Unknown
CVE-2017-1000060
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
EyesOfNetwork (EON) 5.1 Unauthenticated SQL Injection in eonweb leading to remote root
0
Attacker Value
Unknown
CVE-2017-6088
Disclosure Date: April 11, 2017 (last updated November 26, 2024)
Multiple SQL injection vulnerabilities in EyesOfNetwork (aka EON) 5.0 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) bp_name, (2) display, (3) search, or (4) equipment parameter to module/monitoring_ged/ged_functions.php or the (5) type parameter to monitoring_ged/ajax.php.
0
Attacker Value
Unknown
CVE-2015-3996
Disclosure Date: October 27, 2015 (last updated October 05, 2023)
The default AFSecurityPolicy.validatesDomainName configuration for AFSSLPinningModeNone in the AFNetworking framework before 2.5.3, as used in the ownCloud iOS Library, disables verification of a server hostname against the domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
0
Attacker Value
Unknown
CVE-2011-0214
Disclosure Date: July 21, 2011 (last updated October 04, 2023)
CFNetwork in Apple Safari before 5.0.6 on Windows does not properly handle an untrusted attribute of a system root certificate, which allows remote web servers to bypass intended SSL restrictions via a certificate signed by a blacklisted certification authority.
0
Attacker Value
Unknown
CVE-2010-1383
Disclosure Date: July 21, 2011 (last updated October 04, 2023)
CFNetwork in Apple Safari before 5.0.6 on Windows allows remote web servers to execute arbitrary code by replaying the NTLM credentials of a client user, related to a "credential reflection" issue.
0
Attacker Value
Unknown
CVE-2010-1420
Disclosure Date: July 21, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in CFNetwork in Apple Safari before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via a crafted text/plain file.
0
Attacker Value
Unknown
CVE-2010-1800
Disclosure Date: August 25, 2010 (last updated October 04, 2023)
CFNetwork in Apple Mac OS X 10.6.3 and 10.6.4 supports anonymous SSL and TLS connections, which allows man-in-the-middle attackers to redirect a connection and obtain sensitive information via crafted responses.
0
Attacker Value
Unknown
CVE-2008-1479
Disclosure Date: March 24, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in cyberfrogs.net cfnetgs 0.24 allows remote attackers to inject arbitrary web script or HTML via the directory parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2007-2403
Disclosure Date: August 03, 2007 (last updated October 04, 2023)
CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 does not properly validate ftp: URIs, which allows remote attackers to trigger the transmission of arbitrary FTP commands to arbitrary FTP servers.
0
Attacker Value
Unknown
CVE-2007-0464
Disclosure Date: January 30, 2007 (last updated October 04, 2023)
The _CFNetConnectionWillEnqueueRequests function in CFNetwork 129.19 on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (application crash) via a crafted HTTP 301 response, which results in a NULL pointer dereference.
0