Show filters
123 Total Results
Displaying 51-60 of 123
Sort by:
Attacker Value
Unknown
CVE-2018-18541
Disclosure Date: October 20, 2018 (last updated November 27, 2024)
In Teeworlds before 0.6.5, connection packets could be forged. There was no challenge-response involved in the connection build up. A remote attacker could send connection packets from a spoofed IP address and occupy all server slots, or even use them for a reflection attack using map download packets.
0
Attacker Value
Unknown
CVE-2018-13662
Disclosure Date: July 09, 2018 (last updated November 27, 2024)
The mintToken function of a smart contract implementation for WorldOpctionChain, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
0
Attacker Value
Unknown
CVE-2018-13721
Disclosure Date: July 09, 2018 (last updated November 27, 2024)
The mintToken function of a smart contract implementation for GoMineWorld, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
0
Attacker Value
Unknown
CVE-2017-17640
Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter.
0
Attacker Value
Unknown
CVE-2016-9400
Disclosure Date: February 22, 2017 (last updated November 08, 2023)
The CClient::ProcessServerPacket method in engine/client/client.cpp in Teeworlds before 0.6.4 allows remote servers to write to arbitrary physical memory locations and possibly execute arbitrary code via vectors involving snap handling.
0
Attacker Value
Unknown
CVE-2017-3730
Disclosure Date: January 26, 2017 (last updated November 26, 2024)
In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack.
0
Attacker Value
Unknown
CVE-2014-10031
Disclosure Date: January 13, 2015 (last updated October 05, 2023)
Buffer overflow in the IMAPd service in Qualcomm Eudora WorldMail 9.0.333.0 allows remote attackers to execute arbitrary code via a long string in a UID command.
0
Attacker Value
Unknown
CVE-2014-9351
Disclosure Date: December 09, 2014 (last updated October 05, 2023)
engine/server/server.cpp in Teeworlds 0.6.x before 0.6.3 allows remote attackers to read memory and cause a denial of service (crash) via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-6611
Disclosure Date: October 25, 2014 (last updated October 05, 2023)
The BlackBerry World app before 5.0.0.262 on BlackBerry 10 OS 10.2.0, before 5.0.0.263 on BlackBerry 10 OS 10.2.1, and before 5.1.0.53 on BlackBerry 10 OS 10.3.0 does not properly validate download/update requests, which allows user-assisted man-in-the-middle attackers to spoof servers and trigger the download of a crafted app by modifying the client-server data stream.
0
Attacker Value
Unknown
CVE-2014-4885
Disclosure Date: October 21, 2014 (last updated October 05, 2023)
The CPWORLD Close Protection World (aka com.tapatalk.closeprotectionworldcom) application 3.4.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0