Show filters
29 Total Results
Displaying 11-20 of 29
Sort by:
Attacker Value
Unknown

Pixar's Tractor software, versions 2.2 and earlier, contains a stored cross-sit…

Disclosure Date: December 13, 2018 (last updated November 27, 2024)
Pixar's Tractor software, versions 2.2 and earlier, contain a stored cross-site scripting vulnerability in the field that allows a user to add a note to an existing node. The stored information is displayed when a user requests information about the node. An attacker could insert Javascript into this note field that is then saved and displayed to the end user. An attacker might include Javascript that could execute on an authenticated user's system that could lead to website redirects, session cookie hijacking, social engineering, etc. As this is stored with the information about the node, all other authenticated users with access to this data are also vulnerable.
0
Attacker Value
Unknown

CVE-2018-16430

Disclosure Date: September 04, 2018 (last updated November 27, 2024)
GNU Libextractor through 1.7 has an out-of-bounds read vulnerability in EXTRACTOR_zip_extract_method() in zip_extractor.c.
0
Attacker Value
Unknown

CVE-2018-14347

Disclosure Date: July 17, 2018 (last updated November 27, 2024)
GNU Libextractor before 1.7 contains an infinite loop vulnerability in EXTRACTOR_mpeg_extract_method (mpeg_extractor.c).
0
Attacker Value
Unknown

CVE-2018-14346

Disclosure Date: July 17, 2018 (last updated November 27, 2024)
GNU Libextractor before 1.7 has a stack-based buffer overflow in ec_read_file_func (unzip.c).
0
Attacker Value
Unknown

CVE-2018-5329

Disclosure Date: January 15, 2018 (last updated November 26, 2024)
ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) on /CWEBNET/* authenticated pages. A successful CSRF attack can force the user to modify state: creating users, changing an email address, and so forth. If the victim is an administrative account, CSRF can compromise the entire web application.
0
Attacker Value
Unknown

CVE-2018-5328

Disclosure Date: January 15, 2018 (last updated November 26, 2024)
ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows access to various /UserManagement/ privileged modules without authenticating the user; an attacker can misuse these functionalities to perform unauthorized actions, as demonstrated by Edit User Details.
0
Attacker Value
Unknown

CVE-2017-17721

Disclosure Date: December 18, 2017 (last updated November 26, 2024)
CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, assignto, building, domain, jobtype, site, trade, woType, workorderno, or workorderstatus parameter.
0
Attacker Value
Unknown

CVE-2017-17440

Disclosure Date: December 06, 2017 (last updated November 26, 2024)
GNU Libextractor 1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted GIF, IT (Impulse Tracker), NSFE, S3M (Scream Tracker 3), SID, or XM (eXtended Module) file, as demonstrated by the EXTRACTOR_xm_extract_method function in plugins/xm_extractor.c.
0
Attacker Value
Unknown

CVE-2017-15922

Disclosure Date: October 26, 2017 (last updated November 26, 2024)
In GNU Libextractor 1.4, there is an out-of-bounds read in the EXTRACTOR_dvi_extract_method function in plugins/dvi_extractor.c.
0
Attacker Value
Unknown

CVE-2017-15601

Disclosure Date: October 18, 2017 (last updated November 26, 2024)
In GNU Libextractor 1.4, there is a heap-based buffer overflow in the EXTRACTOR_png_extract_method function in plugins/png_extractor.c, related to processiTXt and stndup.
0