Show filters
524 Total Results
Displaying 501-510 of 524
Sort by:
Attacker Value
Unknown

CVE-2006-0891

Disclosure Date: February 25, 2006 (last updated February 22, 2025)
Multiple directory traversal vulnerabilities in NOCC Webmail 1.0 allow remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing NULL (%00) byte in (1) the _SESSION['nocc_theme'] parameter in (a) html/footer.php; and (2) the lang and (3) theme parameters and the (4) Accept-Language HTTP header field, when force_default_lang is disabled, in (b) index.php, as demonstrated by injecting PHP code into a profile and accessing it using the lang parameter in index.php.
0
Attacker Value
Unknown

CVE-2006-0893

Disclosure Date: February 25, 2006 (last updated February 22, 2025)
NOCC Webmail 1.0 allows remote attackers to obtain sensitive information via a direct request to (1) the profiles directory, which leaks e-mail addresses contained in filenames of profiles, and (2) the tmp directory, which lists names of uploaded attachments.
0
Attacker Value
Unknown

CVE-2005-2789

Disclosure Date: September 02, 2005 (last updated February 22, 2025)
BFCommand & Control Server Manager BFCC 1.22_A and earlier, and BFVCC 2.14_B and earlier, allows remote attackers to bypass authentication via (1) an unknown attack vector or (2) a NULL (0x00) as a username.
0
Attacker Value
Unknown

CVE-2005-2790

Disclosure Date: September 02, 2005 (last updated February 22, 2025)
BFCommand & Control Server Manager BFCC 1.22_A and earlier, and BFVCC 2.14_B and earlier, relies on the client to enforce permissions and perform actions such as disconnections, which allows remote attackers to bypass administrative restrictions via a modified client.
0
Attacker Value
Unknown

CVE-2005-2791

Disclosure Date: September 02, 2005 (last updated February 22, 2025)
BFCommand & Control Server Manager BFCC 1.22_A and earlier, and BFVCC 2.14_B and earlier, allows remote attackers to cause a denial of service (refused new connections) via a series of connections and disconnections without sending the login command.
0
Attacker Value
Unknown

CVE-2004-0601

Disclosure Date: December 23, 2004 (last updated February 22, 2025)
distcc before 2.16, when running on 64-bit platforms, does not interpret IP-based access control rules correctly, which could allow remote attackers to bypass intended restrictions.
0
Attacker Value
Unknown

CVE-2004-1714

Disclosure Date: August 11, 2004 (last updated February 22, 2025)
BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Full Control permissions, which allows local users to cause a denial of service (crash) or modify configuration, as demonstrated by modifying firewall.ini to contain a large firewall rule.
Attacker Value
Unknown

CVE-2004-0362

Disclosure Date: April 15, 2004 (last updated February 22, 2025)
Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various RealSecure, Proventia, and BlackICE products, allow remote attackers to execute arbitrary code via a SRV_MULTI response containing a SRV_USER_ONLINE response packet and a SRV_META_USER response packet with long (1) nickname, (2) firstname, (3) lastname, or (4) email address fields, as exploited by the Witty worm.
0
Attacker Value
Unknown

CVE-2003-1556

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in cc_guestbook.pl in CGI City CC GuestBook allows remote attackers to inject arbitrary web script or HTML via the (1) name and (2) homepage_title (webpage title) parameters.
0
Attacker Value
Unknown

CVE-2003-0567

Disclosure Date: August 18, 2003 (last updated February 22, 2025)
Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence of IPv4 packets to an interface on the device, causing the input queue on that interface to be marked as full.
0