Show filters
28 Total Results
Displaying 11-20 of 28
Sort by:
Attacker Value
Unknown
CVE-2018-20369
Disclosure Date: December 23, 2018 (last updated November 27, 2024)
Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi-mod/ldap_load_entry.cgi module. The injection point of the issue is the Add_Update module.
0
Attacker Value
Unknown
CVE-2018-1002207
Disclosure Date: July 25, 2018 (last updated November 27, 2024)
mholt/archiver golang package before e4ef56d48eb029648b0e895bb0b6a393ef0829c3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
0
Attacker Value
Unknown
CVE-2018-1002200
Disclosure Date: July 25, 2018 (last updated November 27, 2024)
plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
0
Attacker Value
Unknown
CVE-2015-0556
Disclosure Date: April 08, 2015 (last updated October 05, 2023)
Open-source ARJ archiver 3.10.22 allows remote attackers to conduct directory traversal attacks via a symlink attack in an ARJ archive.
0
Attacker Value
Unknown
CVE-2015-0557
Disclosure Date: April 08, 2015 (last updated October 05, 2023)
Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in a path in an ARJ archive.
0
Attacker Value
Unknown
CVE-2015-2782
Disclosure Date: April 08, 2015 (last updated October 05, 2023)
Buffer overflow in Open-source ARJ archiver 3.10.22 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ARJ archive.
0
Attacker Value
Unknown
CVE-2014-0619
Disclosure Date: October 23, 2014 (last updated October 05, 2023)
Untrusted search path vulnerability in Hamster Free ZIP Archiver 2.0.1.7 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the current working directory.
0
Attacker Value
Unknown
CVE-2013-5660
Disclosure Date: April 25, 2014 (last updated October 05, 2023)
Buffer overflow in Power Software WinArchiver 3.2 allows remote attackers to execute arbitrary code via a crafted .zip file.
0
Attacker Value
Unknown
CVE-2014-2319
Disclosure Date: March 14, 2014 (last updated October 05, 2023)
The Encrypt Files feature in ConeXware PowerArchiver before 14.02.05 uses legacy ZIP encryption even if the AES 256-bit selection is chosen, which makes it easier for context-dependent attackers to obtain sensitive information via a known-plaintext attack.
0
Attacker Value
Unknown
CVE-2008-0971
Disclosure Date: December 19, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in Barracuda Spam Firewall (BSF) before 3.5.12.007, Message Archiver before 1.2.1.002, Web Filter before 3.3.0.052, IM Firewall before 3.1.01.017, and Load Balancer before 2.3.024 allow remote attackers to inject arbitrary web script or HTML via (1) the Policy Name field in Search Based Retention Policy in Message Archiver; unspecified parameters in the (2) IP Configuration, (3) Administration, (4) Journal Accounts, (5) Retention Policy, and (6) GroupWise Sync components in Message Archiver; (7) input to search operations in Web Filter; and (8) input used in error messages and (9) hidden INPUT elements in (a) Spam Firewall, (b) IM Firewall, and (c) Web Filter.
0