Show filters
29 Total Results
Displaying 11-20 of 29
Sort by:
Attacker Value
Unknown

CVE-2019-13285

Disclosure Date: May 04, 2020 (last updated February 21, 2025)
CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection.
Attacker Value
Unknown

CVE-2020-6856

Disclosure Date: February 06, 2020 (last updated February 21, 2025)
An XML External Entity (XEE) vulnerability exists in the JOC Cockpit component of SOS JobScheduler 1.12 and 1.13.2 allows attackers to read files from the server via an entity declaration in any of the XML documents that are used to specify the run-time settings of jobs and orders.
Attacker Value
Unknown

CVE-2020-6855

Disclosure Date: February 06, 2020 (last updated February 21, 2025)
A large or infinite loop vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attackers to parameterize housekeeping jobs in a way that exhausts system resources and results in a denial of service.
Attacker Value
Unknown

CVE-2020-6854

Disclosure Date: February 05, 2020 (last updated February 21, 2025)
A cross-site scripting (XSS) vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attackers to inject arbitrary web script or HTML via JSON properties available from the REST API.
Attacker Value
Unknown

CVE-2018-14650

Disclosure Date: September 27, 2018 (last updated November 27, 2024)
It was discovered that sos-collector does not properly set the default permissions of newly created files, making all files created by the tool readable by any local user. A local attacker may use this flaw by waiting for a legit user to run sos-collector and steal the collected data in the /var/tmp directory.
0
Attacker Value
Unknown

CVE-2018-13681

Disclosure Date: July 09, 2018 (last updated November 27, 2024)
The mintToken function of a smart contract implementation for SOSCoin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
0
Attacker Value
Unknown

CVE-2017-17967

Disclosure Date: December 28, 2017 (last updated November 26, 2024)
pptreader.dll in Kingsoft WPS Office 10.1.0.6930 allows remote attackers to cause a denial of service via a crafted PPT file, aka CNVD-2017-35482.
0
Attacker Value
Unknown

CVE-2015-7529

Disclosure Date: November 06, 2017 (last updated November 26, 2024)
sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$hostname-$date.
Attacker Value
Unknown

CVE-2015-3171

Disclosure Date: July 25, 2017 (last updated November 26, 2024)
sosreport 3.2 uses weak permissions for generated sosreport archives, which allows local users with access to /var/tmp/ to obtain sensitive information by reading the contents of the archive.
Attacker Value
Unknown

CVE-2014-7436

Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The SOS recette (aka com.sos.recette) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0