Show filters
548 Total Results
Displaying 461-470 of 548
Sort by:
Attacker Value
Unknown
CVE-2009-0420
Disclosure Date: February 05, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the RD-Autos (com_rdautos) 1.5.5 Stable component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.
0
Attacker Value
Unknown
CVE-2009-0311
Disclosure Date: January 27, 2009 (last updated October 04, 2023)
The Backbone service (ftbackbone.exe) in EMC AutoStart before 5.3 SP2 allows remote attackers to execute arbitrary code via a packet with a crafted value that is dereferenced as a function pointer.
0
Attacker Value
Unknown
CVE-2008-5935
Disclosure Date: January 21, 2009 (last updated October 04, 2023)
Facto stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for database/facto.mdb. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2008-4963
Disclosure Date: November 06, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the VLAN Trunking Protocol (VTP) implementation on Cisco IOS and CatOS, when the VTP operating mode is not transparent, allows remote attackers to cause a denial of service (device reload or hang) via a crafted VTP packet sent to a switch interface configured as a trunk port.
0
Attacker Value
Unknown
CVE-2008-4498
Disclosure Date: October 09, 2008 (last updated October 04, 2023)
SQL injection vulnerability in searchresults.php in PHP Autos 2.9.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
0
Attacker Value
Unknown
CVE-2008-2476
Disclosure Date: October 03, 2008 (last updated October 04, 2023)
The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS before E7.7.1.1, (5) Juniper JUNOS, and (6) Wind River VxWorks 5.x through 6.4 does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity) or read private network traffic via a spoofed message that modifies the Forward Information Base (FIB).
0
Attacker Value
Unknown
CVE-2008-3559
Disclosure Date: August 08, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice allow remote attackers to inject arbitrary web script or HTML via the (1) filename parameter to search.asp and the (2) page parameter to order.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2008-0957
Disclosure Date: May 20, 2008 (last updated October 04, 2023)
Multiple stack-based buffer overflows in the PhotoStockPlus Uploader Tool ActiveX control (PSPUploader.ocx) allow remote attackers to execute arbitrary code via unspecified initialization parameters.
0
Attacker Value
Unknown
CVE-2008-2282
Disclosure Date: May 18, 2008 (last updated October 04, 2023)
admin.php in Internet Photoshow and Internet Photoshow Special Edition (SE) allows remote attackers to bypass authentication by setting the login_admin cookie to true.
0
Attacker Value
Unknown
CVE-2008-1765
Disclosure Date: April 23, 2008 (last updated October 04, 2023)
Buffer overflow in Adobe Photoshop Album Starter Edition 3.2, and possibly After Effects CS3, allows user-assisted remote attackers and physically proximate attackers to execute arbitrary code via a BMP file with an invalid image header. NOTE: the related issue in Photoshop CS3 is already covered by CVE-2007-2244.
0