Show filters
117 Total Results
Displaying 101-110 of 117
Sort by:
Attacker Value
Unknown
CVE-2013-2604
Disclosure Date: January 12, 2015 (last updated October 05, 2023)
RealNetworks GameHouse RealArcade Installer (aka ActiveMARK Game Installer) 2.6.0.481 and 3.0.7 uses weak permissions (Create Files/Write Data) for the GameHouse Games directory tree, which allows local users to gain privileges via a Trojan horse DLL in an individual game's directory, as demonstrated by DDRAW.DLL in the Zuma Deluxe directory.
0
Attacker Value
Unknown
CVE-2013-2603
Disclosure Date: January 12, 2015 (last updated October 05, 2023)
The RACInstaller.StateCtrl.1 ActiveX control in InstallerDlg.dll in RealNetworks GameHouse RealArcade Installer 2.6.0.481 performs unexpected type conversions for invalid parameter types, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted arguments to the (1) AddTag, (2) Ping, (3) QueuePause, (4) QueueRemove, (5) QueueTop, (6) RemoveTag, (7) TagRemoved, or (8) message method.
0
Attacker Value
Unknown
CVE-2014-3811
Disclosure Date: September 29, 2014 (last updated October 05, 2023)
Juniper Installer Service (JIS) Client 7.x before 7.4R6 for Windows and Junos Pulse Client before 4.0R6 allows local users to gain privileges via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-4455
Disclosure Date: May 14, 2014 (last updated October 05, 2023)
Katello Installer before 0.0.18 uses world-readable permissions for /etc/pki/tls/private/katello-node.key when deploying a child Pulp node, which allows local users to obtain the private key by reading the file.
0
Attacker Value
Unknown
CVE-2011-0190
Disclosure Date: March 23, 2011 (last updated October 04, 2023)
Install Helper in Installer in Apple Mac OS X before 10.6.7 does not properly process an unspecified URL, which might allow remote attackers to track user logins by logging network traffic from an agent that was intended to send network traffic to an Apple server.
0
Attacker Value
Unknown
CVE-2010-2583
Disclosure Date: November 03, 2010 (last updated October 04, 2023)
Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
0
Attacker Value
Unknown
CVE-2010-1967
Disclosure Date: July 15, 2010 (last updated October 04, 2023)
Unspecified vulnerability in HP Insight Software Installer for Windows before 6.1 allows local users to read or modify data via unknown vectors.
0
Attacker Value
Unknown
CVE-2010-1968
Disclosure Date: July 15, 2010 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in HP Insight Software Installer for Windows before 6.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, a different vulnerability than CVE-2010-1971.
0
Attacker Value
Unknown
CVE-2010-1970
Disclosure Date: July 15, 2010 (last updated October 04, 2023)
Unspecified vulnerability in HP Insight Software Installer for Windows before 6.1 allows local users to read or modify data, and consequently gain privileges, via unknown vectors.
0
Attacker Value
Unknown
CVE-2010-1971
Disclosure Date: July 15, 2010 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in HP Insight Software Installer for Windows before 6.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, a different vulnerability than CVE-2010-1968.
0