Search: "digital"

1129 CVEs found

The Java XML Digital Signature implementation in Sun JDK and JRE 6 before Update 2 does not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attac...

Published: 2007-07-11
Products: 2
Vendors:
sun
CVE-2007-2240
5.8 MEDIUM

The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), does not ...

Published: 2007-08-15
Products: 2
Vendors:
lenovo

Multiple stack-based buffer overflows in the PhotoChannel Networks PNI Digital Media Photo Upload Plugin ActiveX control before 2.0.0.10, as used by multiple retailers, allow remote attackers to execu...

Published: 2007-09-18
Products: 1
Vendors:
photochannel
CVE-2007-5649
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in lostpwd.php in Creative Digital Resources SocketMail 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the lost_id parameter.

Published: 2007-10-23
Products: 1
Vendors:
socketmail

Multiple SQL injection vulnerabilities in Digital Hive 2.0 RC2 and earlier allow (1) remote attackers to execute arbitrary SQL commands via the selectskin parameter to an unspecified program, or (2) r...

Published: 2008-01-16
Products: 1
Vendors:
digitalhive
CVE-2008-0380
10.0 HIGH

Buffer overflow in the Digital Data Communications RtspVaPgCtrl ActiveX control (RtspVapgDecoder.dll 1.1.0.29) allows remote attackers to execute arbitrary code via a long MP4Prefix property.

Published: 2008-01-22
Products: 1
Vendors:
digital_data_communications

The Digital Photo Access Protocol (DPAP) server for iPhoto 4.0.3 allows remote attackers to cause a denial of service (crash) via a malformed dpap: URI, a different vulnerability than CVE-2008-0043.

Published: 2008-02-19
Products: 1
Vendors:
apple
CVE-2008-0987
6.8 MEDIUM

Stack-based buffer overflow in Image Raw in Apple Mac OS X 10.5.2, and Digital Camera RAW Compatibility before Update 2.0 for Aperture 2 and iPhoto 7.1.2, allows remote attackers to execute arbitrary ...

Published: 2008-03-18
Products: 4
Vendors:
apple
CVE-2008-1985
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in base.php in DigitalHive 2.0 RC2 allows remote attackers to inject arbitrary web script or HTML via the mt parameter, possibly related to membres.php.

Published: 2008-04-27
Products: 1
Vendors:
digital_hive
CVE-2008-2415
6.8 MEDIUM

Directory traversal vulnerability in template/purpletech/base_include.php in DigitalHive (aka hive) 2.0 RC2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in t...

Published: 2008-05-22
Products: 1
Vendors:
digitalhive

PHP remote file inclusion vulnerability in src/browser/resource/categories/resource_categories_view.php in Open Digital Assets Repository System (ODARS) 1.0.2, when register_globals is enabled, allows...

Published: 2008-06-27
Products: 1
Vendors:
odars

Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft ...

Published: 2008-09-11
Products: 22
Vendors:
microsoft

gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Offic...

Published: 2008-09-11
Products: 22
Vendors:
microsoft

gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Offic...

Published: 2008-09-11
Products: 20
Vendors:
microsoft

Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2...

Published: 2008-09-11
Products: 22
Vendors:
microsoft

Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image S...

Published: 2008-09-11
Products: 14
Vendors:
microsoft
CVE-2008-4493
6.8 MEDIUM

Microsoft PicturePusher ActiveX control (PipPPush.DLL 7.00.0709), as used in Microsoft Digital Image 2006 Starter Edition, allows remote attackers to force the upload of arbitrary files by using the A...

Published: 2008-10-08
Products: 1
Vendors:
microsoft
CVE-2008-4931
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in the account module in firmCHANNEL Digital Signage 3.24, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via th...

Published: 2008-11-05
Products: 1
Vendors:
firmchannel
CVE-2008-4948
6.9 MEDIUM

fest.pl in digitaldj 0.7.5 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/ddj_fest.tmp temporary file.

Published: 2008-11-05
Products: 1
Vendors:
nostatic
CVE-2008-5100
10.0 HIGH

The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the pathname of a DLL file instead of the digital signature of th...

Published: 2008-11-17
Products: 1
Vendors:
microsoft