Show filters
132 Total Results
Displaying 1-10 of 132
Sort by:
Attacker Value
Unknown
CVE-2019-19906
Disclosure Date: December 19, 2019 (last updated November 08, 2023)
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.
0
Attacker Value
Unknown
CVE-2016-1950
Disclosure Date: March 13, 2016 (last updated October 23, 2024)
Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate.
0
Attacker Value
Unknown
CVE-2016-0802
Disclosure Date: February 07, 2016 (last updated November 25, 2024)
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal bug 25306181.
0
Attacker Value
Unknown
CVE-2016-0801
Disclosure Date: February 07, 2016 (last updated November 25, 2024)
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal bug 25662029.
0
Attacker Value
Unknown
CVE-2014-1252
Disclosure Date: January 24, 2014 (last updated October 05, 2023)
Double free vulnerability in Apple Pages 2.x before 2.1 and 5.x before 5.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Word file.
0
Attacker Value
Unknown
CVE-2013-5145
Disclosure Date: September 19, 2013 (last updated October 05, 2023)
kextd in Kext Management in Apple iOS before 7 does not properly verify authorization for IPC messages, which allows local users to (1) load or (2) unload kernel extensions via a crafted message.
0
Attacker Value
Unknown
CVE-2013-5152
Disclosure Date: September 19, 2013 (last updated October 05, 2023)
Mobile Safari in Apple iOS before 7 allows remote attackers to spoof the URL bar via a crafted web site.
0
Attacker Value
Unknown
CVE-2013-5151
Disclosure Date: September 19, 2013 (last updated October 05, 2023)
Mobile Safari in Apple iOS before 7 does not prevent HTML interpretation of a document served with a text/plain content type, which allows remote attackers to conduct cross-site scripting (XSS) attacks by uploading a file.
0
Attacker Value
Unknown
CVE-2013-5139
Disclosure Date: September 19, 2013 (last updated October 05, 2023)
The IOSerialFamily driver in Apple iOS before 7 allows attackers to execute arbitrary code or cause a denial of service (out-of-bounds array access) via a crafted application.
0
Attacker Value
Unknown
CVE-2013-5157
Disclosure Date: September 19, 2013 (last updated October 05, 2023)
The Twitter subsystem in Apple iOS before 7 does not require API conformity for access to Twitter daemon interfaces, which allows attackers to post Tweets via a crafted app that sends direct requests to the daemon.
0