Show filters
86 Total Results
Displaying 71-80 of 86
Sort by:
Attacker Value
Unknown
CVE-2017-6968
Disclosure Date: April 06, 2017 (last updated November 26, 2024)
GMV Checker ATM Security prior to 5.0.18 allows remote authenticated users to execute arbitrary code via unspecified vectors, aka PT-2017-03.
0
Attacker Value
Unknown
CVE-2016-1143
Disclosure Date: January 30, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in main.rb in Vine MV before 2015-11-08 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-7253
Disclosure Date: November 04, 2015 (last updated October 05, 2023)
The Web Console in Commvault Edge Server 10 R2 allows remote attackers to execute arbitrary OS commands via crafted serialized data in a cookie.
0
Attacker Value
Unknown
CVE-2014-7576
Disclosure Date: October 20, 2014 (last updated October 05, 2023)
The Chien Binh Bakugan 2 LongTieng (aka com.htv.chien.binh.bakugan.ii.hanh.trinh.moi.long.tieng) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-5866
Disclosure Date: September 11, 2014 (last updated October 05, 2023)
The CA DMV (aka gov.ca.dmv) application 2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2012-4226
Disclosure Date: September 03, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Quick Post Widget plugin 1.9.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) Title, (2) Content, or (3) New category field to wordpress/ or (4) query string to wordpress/.
0
Attacker Value
Unknown
CVE-2010-3128
Disclosure Date: August 26, 2010 (last updated October 04, 2023)
Untrusted search path vulnerability in TeamViewer 5.0.8703 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .tvs or .tvc file.
0
Attacker Value
Unknown
CVE-2008-5400
Disclosure Date: December 10, 2008 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in mvnForum before 1.2.1 GA allow remote attackers to (1) create forums, (2) change account privileges, (3) enable accounts, or (4) disable accounts as a product administrator via unspecified vectors, possibly related to HTTP Referer headers.
0
Attacker Value
Unknown
CVE-2008-5399
Disclosure Date: December 10, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the listonlineusers (aka "Who's online") component in mvnForum before 1.2.1 GA allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
0
Attacker Value
Unknown
CVE-2007-0395
Disclosure Date: January 19, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in libraries/grab_globals.lib.php in ComVironment 4.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter.
0