259131
|
- |
|
renren
|
renren_talk
|
Integer signedness error in RenRen Talk 2.9 allows remote attackers to execute arbitrary code via crafted dimensions of a skin file, leading to a heap-based buffer overflow, as demonstrated using a B…
|
CWE-189
Numeric Errors
|
CVE-2012-0915
|
2012-01-25 14:00 |
2012-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259132
|
- |
|
xiaomi
|
mitalk_messenger
|
The Xiaomi MiTalk Messenger (com.xiaomi.channel) application before 2.1.320 for Android does not properly protect data, which allows remote attackers to read or modify messaging information via a cra…
|
CWE-200
Information Exposure
|
CVE-2011-4697
|
2012-01-25 14:00 |
2012-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259133
|
- |
|
hatena
|
callconfirm
|
The CallConfirm (jp.gr.java_conf.ofnhwx.callconfirm) application 2.0.0 for Android does not properly protect data, which allows remote attackers to read or modify allow/block lists via a crafted appl…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-4701
|
2012-01-25 14:00 |
2012-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259134
|
- |
|
nimbuzz
|
nimbuzz
|
The Nimbuzz (com.nimbuzz) application 2.0.8 and 2.0.10 for Android does not properly protect data, which allows remote attackers to read or modify a contact list via a crafted application.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-4702
|
2012-01-25 14:00 |
2012-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259135
|
- |
|
voxofon
|
voxofon
|
The Voxofon (com.voxofon) application before 2.5.2 for Android does not properly protect data, which allows remote attackers to read or modify SMS information via a crafted application.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-4704
|
2012-01-25 14:00 |
2012-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259136
|
- |
|
ming
|
blacklist_free
|
The Ming Blacklist Free (vc.software.blacklist) application 1.8.1 and 1.9.2.1 for Android does not properly protect data, which allows remote attackers to read or modify blacklists and a contact list…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-4705
|
2012-01-25 14:00 |
2012-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259137
|
- |
|
stone-ware
|
webnetwork
|
SQL injection vulnerability in Stoneware webNetwork before 6.0.8.0 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2012-0912
|
2012-01-25 01:56 |
2012-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259138
|
- |
|
stone-ware
|
webnetwork
|
Cross-site request forgery (CSRF) vulnerability in Stoneware webNetwork before 6.0.8.0 allows remote attackers to hijack the authentication of unspecified victims for requests that modify user accoun…
|
CWE-352
Origin Validation Error
|
CVE-2012-0286
|
2012-01-25 01:53 |
2012-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259139
|
- |
|
stone-ware
|
webnetwork
|
Multiple cross-site scripting (XSS) vulnerabilities in Stoneware webNetwork before 6.0.8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2012-0285
|
2012-01-25 00:55 |
2012-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259140
|
- |
|
glucose
|
glucose_2
|
Cross-site scripting (XSS) vulnerability in glucose 2 before stage 6.2 allows remote attackers to inject arbitrary web script or HTML via an RSS feed.
|
CWE-79
Cross-site Scripting
|
CVE-2012-0313
|
2012-01-24 14:00 |
2012-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|