Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown

CVE-2018-11632

Disclosure Date: May 31, 2018 (last updated November 26, 2024)
An issue was discovered in the MULTIDOTS Add Social Share Messenger Buttons Whatsapp and Viber plugin 1.0.8 for WordPress. If an admin user can be tricked into visiting a crafted URL created by an attacker (via spear phishing/social engineering), the attacker can change the plugin settings via wp-admin/admin-post.php CSRF. There's no nonce or capability check in the whatsapp_share_setting_add_update() function.
0
Attacker Value
Unknown

CVE-2013-1085

Disclosure Date: March 29, 2013 (last updated October 05, 2023)
Stack-based buffer overflow in the nim: protocol handler in Novell GroupWise Messenger 2.04 and earlier, and Novell Messenger 2.1.x and 2.2.x before 2.2.2, allows remote attackers to execute arbitrary code via an import command containing a long string in the filename parameter.
0
Attacker Value
Unknown

CVE-2012-1475

Disclosure Date: March 14, 2012 (last updated October 04, 2023)
Unspecified vulnerability in the YagattaTalk Messenger (com.iskoot.yagatta.yagattatalk) application 1.00.01.08 for Android has unknown impact and attack vectors.
0
Attacker Value
Unknown

CVE-2012-0829

Disclosure Date: February 14, 2012 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Mibew Messenger 1.6.4 and earlier allow remote attackers to hijack the authentication of operators for requests that insert cross-site scripting (XSS) sequences via the (1) address or (2) threadid parameters to operator/ban.php; or (3) geolinkparams, (4) title, or (5) chattitle parameters to operator/settings.php.
0
Attacker Value
Unknown

CVE-2011-4697

Disclosure Date: January 25, 2012 (last updated October 04, 2023)
The Xiaomi MiTalk Messenger (com.xiaomi.channel) application before 2.1.320 for Android does not properly protect data, which allows remote attackers to read or modify messaging information via a crafted application.
0
Attacker Value
Unknown

CVE-2012-0268

Disclosure Date: January 19, 2012 (last updated October 04, 2023)
Integer overflow in the CYImage::LoadJPG method in YImage.dll in Yahoo! Messenger before 11.5.0.155, when photo sharing is enabled, might allow remote attackers to execute arbitrary code via a crafted JPG image that triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2011-3179

Disclosure Date: December 08, 2011 (last updated October 04, 2023)
The server process in Novell Messenger 2.1 and 2.2.x before 2.2.1, and Novell GroupWise Messenger 2.04 and earlier, allows remote attackers to read from arbitrary memory locations via a crafted command.
0
Attacker Value
Unknown

CVE-2008-2704

Disclosure Date: June 13, 2008 (last updated October 04, 2023)
Novell GroupWise Messenger (GWIM) before 2.0.3 Hot Patch 1 allows remote attackers to cause a denial of service (crash) via a long user ID, possibly involving a popup alert. NOTE: it is not clear whether this issue crosses privilege boundaries.
0
Attacker Value
Unknown

CVE-2008-2551

Disclosure Date: June 04, 2008 (last updated October 04, 2023)
The DownloaderActiveX Control (DownloaderActiveX.ocx) in Icona SpA C6 Messenger 1.0.0.1 allows remote attackers to force the download and execution of arbitrary files via a URL in the propDownloadUrl parameter with the propPostDownloadAction parameter set to "run."
0
Attacker Value
Unknown

CVE-2006-4511

Disclosure Date: October 05, 2006 (last updated October 04, 2023)
Messenger Agents (nmma.exe) in Novell GroupWise 2.0.2 and 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted HTTP POST request to TCP port 8300 with a modified val parameter, which triggers a null dereference related to "zero-size strings in blowfish routines."
0