Show filters
171 Total Results
Displaying 101-110 of 171
Sort by:
Attacker Value
Unknown
CVE-2013-4409
Disclosure Date: November 04, 2019 (last updated November 27, 2024)
An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests.
0
Attacker Value
Unknown
CVE-2019-7362
Disclosure Date: August 23, 2019 (last updated November 27, 2024)
DLL preloading vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a DLL preloading vulnerability, which may result in code execution.
0
Attacker Value
Unknown
CVE-2019-7363
Disclosure Date: August 23, 2019 (last updated November 27, 2024)
Use-after-free vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a use-after-free vulnerability, which may result in code execution.
0
Attacker Value
Unknown
CVE-2014-5028
Disclosure Date: March 29, 2018 (last updated November 26, 2024)
The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information from repository files by leveraging knowledge of database ids.
0
Attacker Value
Unknown
CVE-2017-18012
Disclosure Date: January 01, 2018 (last updated November 26, 2024)
The Z-URL Preview plugin 1.6.1 for WordPress has XSS via the class.zlinkpreview.php url parameter.
0
Attacker Value
Unknown
CVE-2017-11593
Disclosure Date: July 24, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the Markdown Preview Plus extension before 0.5.7 for Chrome allows remote attackers to inject arbitrary web script or HTML into some web applications via the upload and display of crafted text, markdown, or rst files that are designed to be viewed in the browser as plain text, but that will be converted to HTML without proper sanitization.
0
Attacker Value
Unknown
CVE-2015-8571
Disclosure Date: December 15, 2015 (last updated October 05, 2023)
Integer overflow in Autodesk Design Review (ADR) before 2013 Hotfix 2 allows remote attackers to execute arbitrary code via a crafted biClrUsed value in a BMP file, which triggers a buffer overflow.
0
Attacker Value
Unknown
CVE-2015-8572
Disclosure Date: December 15, 2015 (last updated October 05, 2023)
Multiple buffer overflows in Autodesk Design Review (ADR) before 2013 Hotfix 2 allow remote attackers to execute arbitrary code via crafted RLE data in a (1) BMP or (2) FLI file, (3) encoded scan lines in a PCX file, or (4) DataSubBlock or (5) GlobalColorTable in a GIF file.
0
Attacker Value
Unknown
CVE-2014-9268
Disclosure Date: December 08, 2014 (last updated October 05, 2023)
The AdView.AdViewer.1 ActiveX control in Autodesk Design Review (ADR) before 2013 Hotfix 1 allows remote attackers to execute arbitrary code via a crafted DWF file.
0
Attacker Value
Unknown
CVE-2014-4899
Disclosure Date: October 21, 2014 (last updated October 05, 2023)
The Indian Cement Review (aka com.magzter.indiancementreview) application 3.01 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0