Show filters
192 Total Results
Displaying 51-60 of 192
Sort by:
Attacker Value
Unknown
CVE-2008-2939
Disclosure Date: August 06, 2008 (last updated January 20, 2024)
Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.
0
Attacker Value
Unknown
CVE-2008-0063
Disclosure Date: March 19, 2008 (last updated February 09, 2024)
The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."
0
Attacker Value
Unknown
CVE-2007-6427
Disclosure Date: January 18, 2008 (last updated October 04, 2023)
The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerability than CVE-2007-4990.
0
Attacker Value
Unknown
CVE-2007-4678
Disclosure Date: November 15, 2007 (last updated October 04, 2023)
AppleRAID in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 allows attackers to cause a denial of service (crash) via a crafted striped disk image, which triggers a NULL pointer dereference when it is mounted.
0
Attacker Value
Unknown
CVE-2007-4691
Disclosure Date: November 15, 2007 (last updated October 04, 2023)
The NSURL component in Apple Mac OS X 10.4 through 10.4.10 performs case-sensitive comparisons that allow attackers to bypass intended restrictions for local file system URLs.
0
Attacker Value
Unknown
CVE-2007-2404
Disclosure Date: August 03, 2007 (last updated October 04, 2023)
CRLF injection vulnerability in CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 before 20070731 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in an unspecified context. NOTE: this can be leveraged for cross-site scripting (XSS) attacks.
0
Attacker Value
Unknown
CVE-2007-1863
Disclosure Date: June 27, 2007 (last updated February 16, 2024)
cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.
0
Attacker Value
Unknown
CVE-2007-2401
Disclosure Date: June 25, 2007 (last updated October 04, 2023)
CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1, allows remote attackers to inject arbitrary HTTP headers via LF characters in an XMLHttpRequest request, which are not filtered when serializing headers via the setRequestHeader function. NOTE: this issue can be leveraged for cross-site scripting (XSS) attacks.
0
Attacker Value
Unknown
CVE-2007-2399
Disclosure Date: June 25, 2007 (last updated October 04, 2023)
WebKit in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1 performs an "invalid type conversion", which allows remote attackers to execute arbitrary code via unspecified frame sets that trigger memory corruption.
0
Attacker Value
Unknown
CVE-2007-0753
Disclosure Date: May 24, 2007 (last updated October 04, 2023)
Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows local users to execute arbitrary code via the -i parameter.
0