Show filters
132 Total Results
Displaying 1-10 of 132
Sort by:
Attacker Value
Unknown

CVE-2019-19906

Disclosure Date: December 19, 2019 (last updated November 08, 2023)
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.
Attacker Value
Unknown

CVE-2016-1950

Disclosure Date: March 13, 2016 (last updated October 23, 2024)
Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate.
0
Attacker Value
Unknown

CVE-2016-0802

Disclosure Date: February 07, 2016 (last updated November 25, 2024)
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal bug 25306181.
0
Attacker Value
Unknown

CVE-2016-0801

Disclosure Date: February 07, 2016 (last updated November 25, 2024)
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal bug 25662029.
0
Attacker Value
Unknown

CVE-2014-1252

Disclosure Date: January 24, 2014 (last updated October 05, 2023)
Double free vulnerability in Apple Pages 2.x before 2.1 and 5.x before 5.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Word file.
0
Attacker Value
Unknown

CVE-2013-5145

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
kextd in Kext Management in Apple iOS before 7 does not properly verify authorization for IPC messages, which allows local users to (1) load or (2) unload kernel extensions via a crafted message.
0
Attacker Value
Unknown

CVE-2013-5152

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
Mobile Safari in Apple iOS before 7 allows remote attackers to spoof the URL bar via a crafted web site.
0
Attacker Value
Unknown

CVE-2013-5151

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
Mobile Safari in Apple iOS before 7 does not prevent HTML interpretation of a document served with a text/plain content type, which allows remote attackers to conduct cross-site scripting (XSS) attacks by uploading a file.
0
Attacker Value
Unknown

CVE-2013-5139

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
The IOSerialFamily driver in Apple iOS before 7 allows attackers to execute arbitrary code or cause a denial of service (out-of-bounds array access) via a crafted application.
0
Attacker Value
Unknown

CVE-2013-5157

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
The Twitter subsystem in Apple iOS before 7 does not require API conformity for access to Twitter daemon interfaces, which allows attackers to post Tweets via a crafted app that sends direct requests to the daemon.
0