Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown
CVE-2011-0496
Disclosure Date: January 20, 2011 (last updated October 04, 2023)
Unspecified vulnerability in Sybase EAServer 5.x and 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), and WorkSpace, allows remote attackers to install arbitrary web services and execute arbitrary code, related to a "design vulnerability."
0
Attacker Value
Unknown
CVE-2011-0497
Disclosure Date: January 20, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in Sybase EAServer 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), and WorkSpace, allows remote attackers to read arbitrary files via "../\" (dot dot forward-slash backslash) sequences in a crafted request.
0
Attacker Value
Unknown
CVE-2008-1771
Disclosure Date: April 16, 2008 (last updated October 04, 2023)
Integer overflow in the ws_getpostvars function in Firefly Media Server (formerly mt-daapd) 0.2.4.1 (0.9~r1696-1.2 on Debian) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP POST request with a large Content-Length.
0
Attacker Value
Unknown
CVE-2006-2539
Disclosure Date: May 22, 2006 (last updated October 04, 2023)
Sybase EAServer 5.0 for HP-UX Itanium, 5.2 for IBM AIX, HP-UX PA-RISC, Linux x86, and Sun Solaris SPARC, and 5.3 for Sun Solaris SPARC does not properly protect passwords when they are being entered via the GUI, which allows local users to obtain the cleartext passwords via the getSelectedText function in javax.swing.JPasswordField component.
0
Attacker Value
Unknown
CVE-2006-1829
Disclosure Date: April 19, 2006 (last updated October 04, 2023)
EAServer Manager in Sybase EAServer 5.2 and 5.3 allows remote authenticated users, possibly guests, to obtain password credentials of arbitrary users via unspecified vectors involving (1) connection caches, (2) open password prompts, and (3) stored custom connection profiles.
0
Attacker Value
Unknown
CVE-2005-4408
Disclosure Date: December 20, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in Miraserver 1.0 RC4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php, (2) id parameter to newsitem.php, and (3) cat parameter to article.php.
0
Attacker Value
Unknown
CVE-2005-2297
Disclosure Date: July 19, 2005 (last updated February 22, 2025)
Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary code via a large javascript parameter.
0
Attacker Value
Unknown
CVE-2002-1337
Disclosure Date: March 07, 2003 (last updated February 22, 2025)
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.
0
Attacker Value
Unknown
CVE-2002-1861
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Sybase Enterprise Application Server 4.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").
0
Attacker Value
Unknown
CVE-2001-0404
Disclosure Date: June 18, 2001 (last updated February 22, 2025)
Directory traversal vulnerability in JavaServer Web Dev Kit (JSWDK) 1.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request to the WEB-INF directory.
0