Show filters
171 Total Results
Displaying 101-110 of 171
Sort by:
Attacker Value
Unknown

CVE-2013-4409

Disclosure Date: November 04, 2019 (last updated November 27, 2024)
An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests.
Attacker Value
Unknown

CVE-2019-7362

Disclosure Date: August 23, 2019 (last updated November 27, 2024)
DLL preloading vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a DLL preloading vulnerability, which may result in code execution.
0
Attacker Value
Unknown

CVE-2019-7363

Disclosure Date: August 23, 2019 (last updated November 27, 2024)
Use-after-free vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a use-after-free vulnerability, which may result in code execution.
0
Attacker Value
Unknown

CVE-2014-5028

Disclosure Date: March 29, 2018 (last updated November 26, 2024)
The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information from repository files by leveraging knowledge of database ids.
0
Attacker Value
Unknown

CVE-2017-18012

Disclosure Date: January 01, 2018 (last updated November 26, 2024)
The Z-URL Preview plugin 1.6.1 for WordPress has XSS via the class.zlinkpreview.php url parameter.
0
Attacker Value
Unknown

CVE-2017-11593

Disclosure Date: July 24, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the Markdown Preview Plus extension before 0.5.7 for Chrome allows remote attackers to inject arbitrary web script or HTML into some web applications via the upload and display of crafted text, markdown, or rst files that are designed to be viewed in the browser as plain text, but that will be converted to HTML without proper sanitization.
0
Attacker Value
Unknown

CVE-2015-8571

Disclosure Date: December 15, 2015 (last updated October 05, 2023)
Integer overflow in Autodesk Design Review (ADR) before 2013 Hotfix 2 allows remote attackers to execute arbitrary code via a crafted biClrUsed value in a BMP file, which triggers a buffer overflow.
0
Attacker Value
Unknown

CVE-2015-8572

Disclosure Date: December 15, 2015 (last updated October 05, 2023)
Multiple buffer overflows in Autodesk Design Review (ADR) before 2013 Hotfix 2 allow remote attackers to execute arbitrary code via crafted RLE data in a (1) BMP or (2) FLI file, (3) encoded scan lines in a PCX file, or (4) DataSubBlock or (5) GlobalColorTable in a GIF file.
0
Attacker Value
Unknown

CVE-2014-9268

Disclosure Date: December 08, 2014 (last updated October 05, 2023)
The AdView.AdViewer.1 ActiveX control in Autodesk Design Review (ADR) before 2013 Hotfix 1 allows remote attackers to execute arbitrary code via a crafted DWF file.
0
Attacker Value
Unknown

CVE-2014-4899

Disclosure Date: October 21, 2014 (last updated October 05, 2023)
The Indian Cement Review (aka com.magzter.indiancementreview) application 3.01 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0