Show filters
97 Total Results
Displaying 41-50 of 97
Sort by:
Attacker Value
Unknown

CVE-2018-13602

Disclosure Date: July 09, 2018 (last updated November 27, 2024)
The mint function of a smart contract implementation for MiningToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
Attacker Value
Unknown

CVE-2018-6461

Disclosure Date: February 05, 2018 (last updated November 26, 2024)
March Hare WINCVS before 2.8.01 build 6610, and CVS Suite before 2009R2 build 6610, contains an Insecure Library Loading vulnerability in the wincvs2.exe or wincvs.exe file, which may allow local users to gain privileges via a Trojan horse Python or TCL DLL file in the current working directory.
0
Attacker Value
Unknown

CVE-2014-3121

Disclosure Date: May 14, 2014 (last updated October 05, 2023)
rxvt-unicode before 9.20 does not properly handle OSC escape sequences, which allows user-assisted remote attackers to manipulate arbitrary X window properties and execute arbitrary commands.
0
Attacker Value
Unknown

CVE-2014-2333

Disclosure Date: April 11, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Lazyest Gallery plugin before 1.1.21 for WordPress allows remote attackers to inject arbitrary web script or HTML via an EXIF tag. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2013-1061

Disclosure Date: October 03, 2013 (last updated October 05, 2023)
dbus/SoftwarePropertiesDBus.py in Software Properties 0.92.17 before 0.92.17.3, 0.92.9 before 0.92.9.3, and 0.82.7 before 0.82.7.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
0
Attacker Value
Unknown

CVE-2013-1444

Disclosure Date: September 30, 2013 (last updated October 05, 2023)
A certain Debian patch for txt2man 1.5.5, as used in txt2man 1.5.5-2, 1.5.5-4, and others, allows local users to overwrite arbitrary files via a symlink attack on /tmp/2222.
0
Attacker Value
Unknown

CVE-2011-5264

Disclosure Date: February 12, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in lazyest-backup.php in the Lazyest Backup plugin before 0.2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the xml_or_all parameter.
0
Attacker Value
Unknown

CVE-2012-5586

Disclosure Date: December 26, 2012 (last updated October 05, 2023)
The Services module 6.x-3.x before 6.x-3.3 and 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "access user profiles" permission to access arbitrary users' emails via vectors related to the "user index method" and "the path to the user resource."
0
Attacker Value
Unknown

CVE-2010-4889

Disclosure Date: October 07, 2011 (last updated October 04, 2023)
Unspecified vulnerability in the Tiny Market (hm_tinymarket) extension 0.5.4 and earlier for TYPO3 allows attackers to execute arbitrary code via unknown vectors.
0
Attacker Value
Unknown

CVE-2010-4888

Disclosure Date: October 07, 2011 (last updated October 04, 2023)
SQL injection vulnerability in the Tiny Market (hm_tinymarket) extension 0.5.4 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0