Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2013-2018

Disclosure Date: February 20, 2020 (last updated February 21, 2025)
Multiple SQL injection vulnerabilities in BOINC allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
Attacker Value
Unknown

CVE-2018-1000875

Disclosure Date: December 20, 2018 (last updated November 27, 2024)
Berkeley Open Infrastructure for Network Computing BOINC Server and Website Code version 0.9-1.0.2 contains a CWE-302: Authentication Bypass by Assumed-Immutable Data vulnerability in Website Terms of Service Acceptance Page that can result in Access to any user account. This attack appear to be exploitable via Specially crafted URL. This vulnerability appears to have been fixed in 1.0.3.
0
Attacker Value
Unknown

CVE-2012-2653

Disclosure Date: July 12, 2012 (last updated October 04, 2023)
arpwatch 2.1a15, as used by Red Hat, Debian, Fedora, and possibly others, does not properly drop supplementary groups, which might allow attackers to gain root privileges by leveraging other vulnerabilities in the daemon.
0
Attacker Value
Unknown

CVE-2009-0126

Disclosure Date: January 15, 2009 (last updated October 04, 2023)
The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infrastructure for Network Computing (BOINC) 6.2.14 and 6.4.5 does not check the return value from the OpenSSL RSA_public_decrypt function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
0
Attacker Value
Unknown

CVE-2007-4899

Disclosure Date: September 14, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Boinc Forum 5.10.20 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to forum_forum.php, or the search_string parameter to forum_text_search_action.php in a (2) titles or (3) bodies search.
0
Attacker Value
Unknown

CVE-2001-0916

Disclosure Date: November 21, 2001 (last updated February 22, 2025)
Buffer overflow in Berkeley parallel make (pmake) 2.1.33 and earlier allows a local user to gain root privileges via a long check argument of a shell definition.
0
Attacker Value
Unknown

CVE-2001-0915

Disclosure Date: November 21, 2001 (last updated February 22, 2025)
Format string vulnerability in Berkeley parallel make (pmake) 2.1.33 and earlier allows a local user to gain root privileges via format specifiers in the check argument of a shell definition.
0
Attacker Value
Unknown

CVE-2001-1327

Disclosure Date: May 24, 2001 (last updated February 22, 2025)
pmake before 2.1.35 in Turbolinux 6.05 and earlier is installed with setuid root privileges, which could allow local users to gain privileges by exploiting vulnerabilities in pmake or programs that are used by pmake.
0
Attacker Value
Unknown

CVE-2000-0076

Disclosure Date: December 30, 1999 (last updated February 22, 2025)
nviboot boot script in the Debian nvi package allows local users to delete files via malformed entries in vi.recover.
0