Show filters
545 Total Results
Displaying 401-410 of 545
Sort by:
Attacker Value
Unknown

CVE-2014-4867

Disclosure Date: October 10, 2014 (last updated October 05, 2023)
Cryoserver Security Appliance 7.3.x uses weak permissions for /etc/init.d/cryoserver, which allows local users to gain privileges by leveraging access to the support account and running the /bin/cryo-mgmt program.
0
Attacker Value
Unknown

CVE-2014-6054

Disclosure Date: October 06, 2014 (last updated October 05, 2023)
The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier allows remote attackers to cause a denial of service (divide-by-zero error and server crash) via a zero value in the scaling factor in a (1) PalmVNCSetScaleFactor or (2) SetScale message.
0
Attacker Value
Unknown

CVE-2014-6876

Disclosure Date: October 02, 2014 (last updated October 05, 2023)
The American Express Serve (aka com.serve.mobile) application @7F0901E4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-6051

Disclosure Date: September 30, 2014 (last updated October 05, 2023)
Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement for a large screen size, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2014-6055

Disclosure Date: September 30, 2014 (last updated October 05, 2023)
Multiple stack-based buffer overflows in the File Transfer feature in rfbserver.c in LibVNCServer 0.9.9 and earlier allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a (1) long file or (2) directory name or the (3) FileTime attribute in a rfbFileTransferOffer message.
0
Attacker Value
Unknown

CVE-2012-1032

Disclosure Date: September 17, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Euroling SiteSeeker module 3.x before 3.4.5 for EPiServer allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2013-4730

Disclosure Date: May 15, 2014 (last updated October 05, 2023)
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USER command.
0
Attacker Value
Unknown

CVE-2014-3207

Disclosure Date: May 08, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in wserver.ml in SKS Keyserver before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to pks/lookup/undefined1.
0
Attacker Value
Unknown

CVE-2013-5954

Disclosure Date: April 25, 2014 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.11 and earlier allow remote attackers to hijack the authentication of administrators for requests that delete (1) users via admin/agency-user-unlink.php, (2) advertisers via admin/advertiser-delete.php, (3) banners via admin/banner-delete.php, (4) campaigns via admin/campaign-delete.php, (5) channels via admin/channel-delete.php, (6) affiliate websites via admin/affiliate-delete.php, or (7) zones via admin/zone-delete.php.
0
Attacker Value
Unknown

CVE-2014-0777

Disclosure Date: April 11, 2014 (last updated October 05, 2023)
The Modbus slave/outstation driver in the OPC Drivers 1.0.20 and earlier in IOServer OPC Server allows remote attackers to cause a denial of service (out-of-bounds read and daemon crash) via a crafted packet.
0