CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Cross-site scripting (XSS) vulnerability in analyse.php in CAcert 20080921, and possibly other versions before 20080928, allows remote attackers to inject arbitrary web script or HTML via the CN (CommonName) field in the subject of an X.509 certificate.
tnftpd before 20080929 splits large command strings into multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unknown vectors, probably involving a crafted ftp:// link to a tnftpd server.
Unreal_engine, Unreal_tournament, Unreal_tournament_2003, Unreal_tournament_2004, Unreal_tournament_3, Unreal_tournament_server, Fuel_of_war
2018-10-11
N/A
N/A
Unreal engine 3, as used in Unreal Tournament 3 1.3, Frontlines: Fuel of War 1.1.1, and other products, allows remote attackers to cause a denial of service (server exit) via a packet with a large length value that triggers a memory allocation failure.
fhttpd 0.4.2 allows remote attackers to cause a denial of service (crash) via an Authorization HTTP header with an invalid character after the Basic value.
Baidu_hi, Baidu_hi_im, Baidu_ime, Baidu_navigation, Baidunetdisk, Baidux, Kity_minder, Simeji, Soba_search_bar, Spark_browser
2018-10-11
N/A
N/A
NetService.dll in Baidu Hi IM allows remote servers to cause a denial of service (client crash) via a crafted login response that triggers a divide-by-zero error.
File_transfer_appliance, Fta, Ftp_server, Kiteworks, Kiteworks_appliance, Managed_file_transfer, Secure_file_transfer_appliance
2017-08-17
N/A
N/A
courier/1000@/api_error_email.html (aka "error reporting page") in Accellion File Transfer Appliance FTA_7_0_178, and possibly other versions before FTA_7_0_189, allows remote attackers to send spam e-mail via modified description and client_email parameters.
Pariah, Unreal_engine, Unreal_tournament, Unreal_tournament_2003, Unreal_tournament_2004, Unreal_tournament_3, Unreal_tournament_server, Warpath, Dead_mans_hand, Shadow_ops, Postal
2018-10-11
N/A
N/A
The Unreal engine, as used in Unreal Tournament 3 1.3, Unreal Tournament 2003 and 2004, Dead Man's Hand, Pariah, WarPath, Postal2, and Shadow Ops, allows remote authenticated users to cause a denial of service (server exit) via multiple file downloads from the server, which triggers an assertion failure when the Closing flag in UnChan.cpp is set.
Skalfa Software SkaLinks Exchange Script 1.5 allows remote attackers to add new administrators and gain privileges via a direct request to admin/register.php.
Security_gateway, Gaia, Capsule_docs, Capsule_docs_standalone_client, Capsule_workspace, Check_point, Check_point_integrity_client, Check_point_vpn, Check_point_vpn-1_pro, Connectra_ngx
2018-10-11
N/A
N/A
Buffer overflow in multiscan.exe in Check Point ZoneAlarm Security Suite 7.0.483.000 and 8.0.020.000 allows local users to execute arbitrary code via a file or directory with a long path. NOTE: some of these details are obtained from third party information.
HyperStop Web Host Directory 1.2 allows remote attackers to bypass authentication and download a database backup via a direct request to admin/backup/db.