Show filters
555 Total Results
Displaying 531-540 of 555
Sort by:
Attacker Value
Unknown
CVE-2007-5906
Disclosure Date: November 09, 2007 (last updated October 04, 2023)
Xen 3.1.1 allows virtual guest system users to cause a denial of service (hypervisor crash) by using a debug register (DR7) to set certain breakpoints.
0
Attacker Value
Unknown
CVE-2007-3919
Disclosure Date: October 28, 2007 (last updated October 04, 2023)
(1) xenbaked and (2) xenmon.py in Xen 3.1 and earlier allow local users to truncate arbitrary files via a symlink attack on /tmp/xenq-shm.
0
Attacker Value
Unknown
CVE-2007-4993
Disclosure Date: September 27, 2007 (last updated October 04, 2023)
pygrub (tools/pygrub/src/GrubConf.py) in Xen 3.0.3, when booting a guest domain, allows local users with elevated privileges in the guest domain to execute arbitrary commands in domain 0 via a crafted grub.conf file whose contents are used in exec statements.
0
Attacker Value
Unknown
CVE-2007-2986
Disclosure Date: June 01, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in lib/live_status.lib.php in AdminBot MX 9.0.5 allows remote attackers to execute arbitrary PHP code via a URL in the ROOT parameter.
0
Attacker Value
Unknown
CVE-2007-0998
Disclosure Date: March 20, 2007 (last updated October 04, 2023)
The VNC server implementation in QEMU, as used by Xen and possibly other environments, allows local users of a guest operating system to read arbitrary files on the host operating system via unspecified vectors related to QEMU monitor mode, as demonstrated by mapping files to a CDROM device. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2007-0332
Disclosure Date: January 18, 2007 (last updated October 04, 2023)
(1) admin/adminlien.php3 and (2) admin/modif.php3 in liens_dynamiques 2.1 do not require authentication, which allows remote attackers to perform unauthorized administrative actions using a direct request.
0
Attacker Value
Unknown
CVE-2007-0331
Disclosure Date: January 18, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in liens.php3 in liens_dynamiques 2.1 allows remote attackers to inject arbitrary web script or HTML by using the ajouter=1 query string and the add menu.
0
Attacker Value
Unknown
CVE-2006-5797
Disclosure Date: November 08, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in default.asp in Xenis.creator CMS allow remote attackers to execute arbitrary SQL commands via the (1) nav, (2) s, or (3) print parameters.
0
Attacker Value
Unknown
CVE-2006-5799
Disclosure Date: November 08, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in default.asp in xenis.creator CMS allow remote attackers to inject arbitrary web script or HTML via the (1) contid or (2) search parameters.
0
Attacker Value
Unknown
CVE-2006-5798
Disclosure Date: November 08, 2006 (last updated October 04, 2023)
SQL injection vulnerability in default.asp in Xenis.creator CMS allows remote attackers to execute arbitrary SQL commands via the contid parameter.
0