Show filters
76 Total Results
Displaying 61-70 of 76
Sort by:
Attacker Value
Unknown
CVE-2011-4220
Disclosure Date: November 01, 2011 (last updated October 04, 2023)
Investintech.com SlimPDF Reader does not properly restrict the arguments to unspecified function calls, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.
0
Attacker Value
Unknown
CVE-2011-4216
Disclosure Date: November 01, 2011 (last updated October 04, 2023)
Investintech.com SlimPDF Reader does not properly restrict write operations, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.
0
Attacker Value
Unknown
CVE-2011-4219
Disclosure Date: November 01, 2011 (last updated October 04, 2023)
Investintech.com SlimPDF Reader does not prevent faulting-address data from affecting branch selection, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.
0
Attacker Value
Unknown
CVE-2011-4217
Disclosure Date: November 01, 2011 (last updated October 04, 2023)
Investintech.com SlimPDF Reader does not properly restrict read operations during block data moves, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.
0
Attacker Value
Unknown
CVE-2011-4218
Disclosure Date: November 01, 2011 (last updated October 04, 2023)
Investintech.com SlimPDF Reader does not prevent faulting-instruction data from affecting write operations, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.
0
Attacker Value
Unknown
CVE-2010-2945
Disclosure Date: August 30, 2010 (last updated October 04, 2023)
The default configuration of SLiM before 1.3.2 places ./ (dot slash) at the beginning of the default_path option, which might allow local users to gain privileges via a Trojan horse program in the current working directory, related to slim.conf and cfg.cpp.
0
Attacker Value
Unknown
CVE-2009-1756
Disclosure Date: May 22, 2009 (last updated October 04, 2023)
SLiM Simple Login Manager 1.3.0 places the X authority magic cookie (mcookie) on the command line when invoking xauth from (1) app.cpp and (2) switchuser.cpp, which allows local users to access the X session by listing the process and its arguments.
0
Attacker Value
Unknown
CVE-2008-5708
Disclosure Date: December 24, 2008 (last updated October 04, 2023)
redirect.php in SlimCMS 1.0.0 does not require authentication, which allows remote attackers to create administrative users by using the newusername and newpassword parameters and setting the newisadmin parameter to 1.
0
Attacker Value
Unknown
CVE-2008-5491
Disclosure Date: December 12, 2008 (last updated October 04, 2023)
SQL injection vulnerability in edit.php in SlimCMS 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the pageID parameter.
0
Attacker Value
Unknown
CVE-2006-6988
Disclosure Date: February 09, 2007 (last updated October 04, 2023)
Cross-domain vulnerability in Slim Browser 4.07 build 100 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, a similar vulnerability to CVE-2006-3280.
0