Show filters
75 Total Results
Displaying 61-70 of 75
Sort by:
Attacker Value
Unknown
CVE-2017-5858
Disclosure Date: February 09, 2017 (last updated November 26, 2024)
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for Converse.js (0.8.0 - 1.0.6, 2.0.0 - 2.0.4).
0
Attacker Value
Unknown
CVE-2014-7113
Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The NASA Universe Wallpapers Xeus (aka com.xeusNASA) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-7064
Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The ben10 omniverse walkthrough (aka com.wben10omniverse2walkthrough) application 0.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-6022
Disclosure Date: September 22, 2014 (last updated October 05, 2023)
The Versent Books (aka com.versentbooks) application 1.1.99 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2013-3659
Disclosure Date: August 09, 2013 (last updated October 05, 2023)
The NTT DOCOMO overseas usage application 2.0.0 through 2.0.4 for Android does not properly connect to Wi-Fi access points, which allows remote attackers to obtain sensitive information by leveraging presence in an 802.11 network's coverage area.
0
Attacker Value
Unknown
CVE-2012-5332
Disclosure Date: October 08, 2012 (last updated October 05, 2023)
at32 Reverse Proxy 1.060.310 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a long string in an HTTP header field, as demonstrated using the If-Unmodified-Since field.
0
Attacker Value
Unknown
CVE-2009-5090
Disclosure Date: September 12, 2011 (last updated October 04, 2023)
SQL injection vulnerability in editcomments.php in Bloggeruniverse Beta 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter and possibly other unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-4085
Disclosure Date: November 29, 2009 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in assets/plugins/mp3_id/mp3_id.php in PHP Traverser 0.8.0 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[BASE] parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2009-3531
Disclosure Date: October 02, 2009 (last updated October 04, 2023)
SQL injection vulnerability in vnews.php in Universe CMS 1.0.6 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown
CVE-2005-4325
Disclosure Date: December 17, 2005 (last updated February 22, 2025)
Multiple unspecified vulnerabilities in Driverse before 0.56b have unknown impact and attack vectors, related to (1) a "ptrace exploit" and (2) "some other potential security problems."
0