Show filters
77 Total Results
Displaying 61-70 of 77
Sort by:
Attacker Value
Unknown

CVE-2007-2808

Disclosure Date: May 22, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in gnatsweb.pl in Gnatsweb 4.00 and Gnats 4.1.99 allows remote attackers to inject arbitrary web script or HTML via the database parameter.
0
Attacker Value
Unknown

CVE-2007-2560

Disclosure Date: May 09, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in theme/acgv.php in ACGVannu 1.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the rubrik parameter.
0
Attacker Value
Unknown

CVE-2007-0698

Disclosure Date: February 03, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in ACGVannu 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via the id_mod parameter to templates/modif.html, and other unspecified vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2007-0697

Disclosure Date: February 03, 2007 (last updated October 04, 2023)
index2.php in ACGVannu 1.3 and earlier allows remote attackers to change the password or profile of a user via a modified id parameter, related to templates/modif.html. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2007-0577

Disclosure Date: January 30, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in function.inc.php in ACGVclick 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
0
Attacker Value
Unknown

CVE-2006-4638

Disclosure Date: September 08, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in article.php in ACGV News 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the PathNews parameter.
0
Attacker Value
Unknown

CVE-2006-4637

Disclosure Date: September 08, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in ACGV News 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the PathNews parameter in (1) header.php or (2) news.php. NOTE: portions of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2006-1060

Disclosure Date: April 11, 2006 (last updated October 04, 2023)
Heap-based buffer overflow in zgv before 5.8 and xzgv before 0.8 might allow user-assisted attackers to execute arbitrary code via a JPEG image with more than 3 output components, such as a CMYK or YCCK color space, which causes less memory to be allocated than required.
0
Attacker Value
Unknown

CVE-2005-0385

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Buffer overflow in luxman before 0.41, if used with certain insecure svgalib libraries, allows local users to execute arbitrary code via a long -f command line argument.
0
Attacker Value
Unknown

CVE-2004-1095

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Multiple integer overflows in (1) readbmp.c, (2) readgif.c, (3) readgif.c, (4) readmrf.c, (5) readpcx.c, (6) readpng.c,(7) readpnm.c, (8) readprf.c, (9) readtiff.c, (10) readxbm.c, (11) readxpm.c in zgv 5.8 allow remote attackers to execute arbitrary code via certain image headers that cause calculations to be overflowed and small buffers to be allocated, leading to buffer overflows. NOTE: CVE-2004-0994 and CVE-2004-1095 identify sets of bugs that only partially overlap, despite having the same developer. Therefore, they should be regarded as distinct.
0