Show filters
91 Total Results
Displaying 71-80 of 91
Sort by:
Attacker Value
Unknown
CVE-2014-9437
Disclosure Date: January 02, 2015 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the Sliding Social Icons plugin 1.61 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings via unspecified vectors or (2) conduct cross-site scripting (XSS) attacks via the sc_social_slider_margin parameter in a wpbs_save_settings action in the wpbs_panel page to wp-admin/admin.php.
0
Attacker Value
Unknown
CVE-2014-0758
Disclosure Date: February 24, 2014 (last updated October 05, 2023)
An ActiveX control in GenLaunch.htm in ICONICS GENESIS32 8.0, 8.02, 8.04, and 8.05 allows remote attackers to execute arbitrary programs via a crafted HTML document.
0
Attacker Value
Unknown
CVE-2013-4986
Disclosure Date: October 04, 2013 (last updated October 05, 2023)
Stack-based buffer overflow in PDFAX0722_IconCool.dll 7.22.1125.2121 in IconCool PDFCool Studio 3.32 Build 130330 and earlier allows remote attackers to execute arbitrary code via a crafted PDF file.
0
Attacker Value
Unknown
CVE-2012-3018
Disclosure Date: July 31, 2012 (last updated October 04, 2023)
The lockout-recovery feature in the Security Configurator component in ICONICS GENESIS32 9.22 and earlier and BizViz 9.22 and earlier uses an improper encryption algorithm for generation of an authentication code, which allows local users to bypass intended access restrictions and obtain administrative access by predicting a challenge response.
0
Attacker Value
Unknown
CVE-2012-2614
Disclosure Date: July 12, 2012 (last updated October 04, 2023)
Buffer overflow in programmer.exe in Lattice Diamond Programmer 1.4.2 allows user-assisted remote attackers to cause a denial of service (application crash) and execute arbitrary code via a long string in a version attribute of an ispXCF element in an .xcf file.
0
Attacker Value
Unknown
CVE-2012-2915
Disclosure Date: May 21, 2012 (last updated October 04, 2023)
Stack-based buffer overflow in Lattice Semiconductor PAC-Designer 6.2.1344 allows remote attackers to execute arbitrary code via a long string in a Value tag in a SymbolicSchematicData definition tag in PAC Design (.pac) file.
0
Attacker Value
Unknown
CVE-2011-5088
Disclosure Date: April 18, 2012 (last updated October 04, 2023)
The GENESIS32 IcoSetServer ActiveX control in ICONICS GENESIS32 9.21 and BizViz 9.21 configures the trusted zone on the basis of user input, which allows remote attackers to execute arbitrary code via a crafted web site, related to a "Workbench32/WebHMI component SetTrustedZone Policy vulnerability."
0
Attacker Value
Unknown
CVE-2011-5089
Disclosure Date: April 18, 2012 (last updated October 04, 2023)
Buffer overflow in the Security Login ActiveX controls in ICONICS GENESIS32 8.05, 9.0, 9.1, and 9.2 and BizViz 8.05, 9.0, 9.1, and 9.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long password.
0
Attacker Value
Unknown
CVE-2011-2089
Disclosure Date: May 13, 2011 (last updated October 04, 2023)
Stack-based buffer overflow in the SetActiveXGUID method in the VersionInfo ActiveX control in GenVersion.dll 8.0.138.0 in the WebHMI subsystem in ICONICS BizViz 9.x before 9.22 and GENESIS32 9.x before 9.22 allows remote attackers to execute arbitrary code via a long string in the argument. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2011-0651
Disclosure Date: January 28, 2011 (last updated October 04, 2023)
Buffer overflow in the key exchange functionality in Icon Labs Iconfidant SSL Server before 1.3.0 allows remote attackers to execute arbitrary code via a client master key packet in which the sum of unspecified length fields is greater than a certain value.
0