Show filters
81 Total Results
Displaying 51-60 of 81
Sort by:
Attacker Value
Unknown
CVE-2017-9576
Disclosure Date: June 16, 2017 (last updated November 08, 2023)
The "Middleton Community Bank Mobile Banking" by Middleton Community Bank app 3.0.0 -- aka middleton-community-bank-mobile-banking/id721843238 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-6784
Disclosure Date: September 29, 2014 (last updated October 05, 2023)
The Fermononrespiri Mobile (aka com.tapatalk.rmonlineitforums) application 3.8.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2012-3382
Disclosure Date: July 12, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the ProcessRequest function in mcs/class/System.Web/System.Web/HttpForbiddenHandler.cs in Mono 2.10.8 and earlier allows remote attackers to inject arbitrary web script or HTML via a file with a crafted name and a forbidden extension, which is not properly handled in an error message.
0
Attacker Value
Unknown
CVE-2011-4712
Disclosure Date: December 08, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in Oxide WebServer allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in an HTTP request.
0
Attacker Value
Unknown
CVE-2011-4001
Disclosure Date: December 01, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in HP no Mawashimono Nikki 6.6 and earlier allows remote attackers to read and modify arbitrary files via unspecified vectors.
0
Attacker Value
Unknown
CVE-2011-4002
Disclosure Date: November 30, 2011 (last updated October 04, 2023)
HP no Mawashimono Nikki 6.6 and earlier allows remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injection vulnerability."
0
Attacker Value
Unknown
CVE-2011-0992
Disclosure Date: April 13, 2011 (last updated October 04, 2023)
Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denial of service (plugin crash) or obtain sensitive information via vectors related to member data in a resurrected MonoThread instance.
0
Attacker Value
Unknown
CVE-2011-0990
Disclosure Date: April 13, 2011 (last updated October 04, 2023)
Race condition in the FastCopy optimization in the Array.Copy method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to trigger a buffer overflow and modify internal data structures, and cause a denial of service (plugin crash) or corrupt the internal state of the security manager, via a crafted media file in which a thread makes a change after a type check but before a copy action.
0
Attacker Value
Unknown
CVE-2011-0989
Disclosure Date: April 13, 2011 (last updated October 04, 2023)
The RuntimeHelpers.InitializeArray method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, does not properly restrict data types, which allows remote attackers to modify internal read-only data structures, and cause a denial of service (plugin crash) or corrupt the internal state of the security manager, via a crafted media file, as demonstrated by modifying a C# struct.
0
Attacker Value
Unknown
CVE-2011-0991
Disclosure Date: April 13, 2011 (last updated October 04, 2023)
Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to finalizing and then resurrecting a DynamicMethod instance.
0