Show filters
28 Total Results
Displaying 11-20 of 28
Sort by:
Attacker Value
Unknown

CVE-2017-1000026

Disclosure Date: July 17, 2017 (last updated November 26, 2024)
Chef Software's mixlib-archive versions 0.3.0 and older are vulnerable to a directory traversal attack allowing attackers to overwrite arbitrary files by using ".." in tar archive entries
Attacker Value
Unknown

CVE-2012-2120

Disclosure Date: May 18, 2012 (last updated October 04, 2023)
latex2man in texlive-extra-utils 2011.20120322, and possibly other versions or packages, when used with the H or T option, allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
0
Attacker Value
Unknown

CVE-2010-2695

Disclosure Date: July 12, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the SFTP/SSH2 virtual server in Xlight FTP Server 3.5.0, 3.5.5, and possibly other versions before 3.6 allows remote authenticated users to read, overwrite, or delete arbitrary files via .. (dot dot) sequences in the (1) ls, (2) rm, (3) rename, and other unspecified commands.
0
Attacker Value
Unknown

CVE-2009-4795

Disclosure Date: April 22, 2010 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow remote attackers to execute arbitrary SQL commands via the (1) USER (aka username) or (2) PASS (aka password) command.
0
Attacker Value
Unknown

CVE-2008-0604

Disclosure Date: February 06, 2008 (last updated October 04, 2023)
The LDAP authentication feature in XLight FTP Server before 2.83, when used with some unspecified LDAP servers, does not check for blank passwords, which allows remote attackers to bypass intended access restrictions.
0
Attacker Value
Unknown

CVE-2007-5940

Disclosure Date: November 13, 2007 (last updated October 04, 2023)
feynmf.pl in feynmf 1.08, as used in TeXLive 2007, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on the feynmf$$.pl temporary file.
0
Attacker Value
Unknown

CVE-2007-5935

Disclosure Date: November 13, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in hpc.c in dvips in teTeX and TeXlive 2007 and earlier allows user-assisted attackers to execute arbitrary code via a DVI file with a long href tag.
0
Attacker Value
Unknown

CVE-2007-5937

Disclosure Date: November 13, 2007 (last updated October 04, 2023)
Multiple buffer overflows in dvi2xx.c in dviljk in teTeX and TeXlive 2007 and earlier might allow user-assisted attackers to execute arbitrary code via a crafted DVI input file.
0
Attacker Value
Unknown

CVE-2007-5936

Disclosure Date: November 13, 2007 (last updated October 04, 2023)
dvips in teTeX and TeXlive 2007 and earlier allows local users to obtain sensitive information and modify certain data by creating certain temporary files before they are processed by dviljk, which can then be read or modified in place.
0
Attacker Value
Unknown

CVE-2007-4314

Disclosure Date: August 13, 2007 (last updated October 04, 2023)
pixlie.php in Pixlie 1.7 allows remote attackers to trigger the reading and JPEG image processing of files in a remote directory tree via a URL in the root parameter. NOTE: this can be leveraged for traffic amplification or other denial of service.
0