Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown

CVE-2017-12836

Disclosure Date: August 24, 2017 (last updated November 26, 2024)
CVS 1.12.x, when configured to use SSH for remote repositories, might allow remote attackers to execute arbitrary code via a repository URL with a crafted hostname, as demonstrated by "-oProxyCommand=id;localhost:/bar."
0
Attacker Value
Unknown

CVE-2012-0804

Disclosure Date: May 29, 2012 (last updated October 04, 2023)
Heap-based buffer overflow in the proxy_connect function in src/client.c in CVS 1.11 and 1.12 allows remote HTTP proxy servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTTP response.
0
Attacker Value
Unknown

CVE-2006-5190

Disclosure Date: October 10, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in the (a) banner_manager.php, (b) banner_statistics.php, (c) countries.php, (d) currencies.php, (e) languages.php, (f) manufacturers.php, (g) newsletters.php, (h) orders_status.php, (i) products_attributes.php, (j) products_expected.php, (k) reviews.php, (l) specials.php, (m) stats_products_purchased.php, (n) stats_products_viewed.php, (o) tax_classes.php, (p) tax_rates.php, or (q) zones.php scripts in /admin, and the (2) zpage parameter in (r) admin/geo_zones.php.
0
Attacker Value
Unknown

CVE-2005-2693

Disclosure Date: August 26, 2005 (last updated February 22, 2025)
cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack.
0
Attacker Value
Unknown

CVE-2004-1342

Disclosure Date: April 27, 2005 (last updated February 22, 2025)
CVS 1.12 and earlier on Debian GNU/Linux, when using the repouid patch, allows remote attackers to bypass authentication via the pserver access method.
0
Attacker Value
Unknown

CVE-2004-1471

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commit access to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a wrapper line.
0
Attacker Value
Unknown

CVE-2004-1343

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
CVS 1.12 and earlier on Debian GNU/Linux does not properly handle when a mapping for the current repository does not exist in the cvs-repouids file, which allows remote attackers to cause a denial of service (server crash).
0
Attacker Value
Unknown

CVE-2004-0417

Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could cause temporary data to remain undeleted and consume disk space.
0
Attacker Value
Unknown

CVE-2004-0416

Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2004-0418

Disclosure Date: August 06, 2004 (last updated February 22, 2025)
serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data.
0