Show filters
69 Total Results
Displaying 51-60 of 69
Sort by:
Attacker Value
Unknown
CVE-2015-7520
Disclosure Date: April 12, 2016 (last updated November 25, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in the (1) RadioGroup and (2) CheckBoxMultipleChoice classes in Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x before 7.2.0 allow remote attackers to inject arbitrary web script or HTML via a crafted "value" attribute in a <input> element.
0
Attacker Value
Unknown
CVE-2014-9706
Disclosure Date: March 31, 2015 (last updated October 05, 2023)
The build_index_from_tree function in index.py in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a commit with a directory path starting with .git/, which is not properly handled when checking out a working tree.
0
Attacker Value
Unknown
CVE-2015-0838
Disclosure Date: March 31, 2015 (last updated October 05, 2023)
Buffer overflow in the C implementation of the apply_delta function in _pack.c in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a crafted pack file.
0
Attacker Value
Unknown
CVE-2012-2095
Disclosure Date: April 07, 2014 (last updated October 05, 2023)
The SetWiredProperty function in the D-Bus interface in WICD before 1.7.2 allows local users to write arbitrary configuration settings and gain privileges via a crafted property name in a dbus message.
0
Attacker Value
Unknown
CVE-2013-4413
Disclosure Date: March 11, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in controller/concerns/render_redirect.rb in the Wicked gem before 1.0.1 for Ruby allows remote attackers to read arbitrary files via a %2E%2E%2F (encoded dot dot slash) in the step.
0
Attacker Value
Unknown
CVE-2013-2055
Disclosure Date: February 10, 2014 (last updated October 05, 2023)
Unspecified vulnerability in Apache Wicket 1.4.x before 1.4.23, 1.5.x before 1.5.11, and 6.x before 6.8.0 allows remote attackers to obtain sensitive information via vectors that cause raw HTML templates to be rendered without being processed and reading the information that is outside of wicket:panel markup.
0
Attacker Value
Unknown
CVE-2012-3373
Disclosure Date: September 19, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.21 and 1.5.x before 1.5.8 allows remote attackers to inject arbitrary web script or HTML via vectors involving a %00 sequence in an Ajax link URL associated with a Wicket app.
0
Attacker Value
Unknown
CVE-2012-0813
Disclosure Date: June 29, 2012 (last updated October 04, 2023)
Wicd before 1.7.1 saves sensitive information in log files in /var/log/wicd, which allows context-dependent attackers to obtain passwords and other sensitive information.
0
Attacker Value
Unknown
CVE-2012-0047
Disclosure Date: March 23, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the wicket:pageMapName parameter.
0
Attacker Value
Unknown
CVE-2012-1089
Disclosure Date: March 23, 2012 (last updated October 04, 2023)
Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-application files via a relative pathname in a URL for a Wicket resource that corresponds to a null package.
0