Show filters
144 Total Results
Displaying 101-110 of 144
Sort by:
Attacker Value
Unknown
CVE-2016-8587
Disclosure Date: April 28, 2017 (last updated November 26, 2024)
dlp_policy_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via an archive file containing a symlink to /eng_ptn_stores/prod/sensorSDK/data/ or /eng_ptn_stores/prod/sensorSDK/backup_pol/.
0
Attacker Value
Unknown
CVE-2016-8593
Disclosure Date: April 28, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via a .. (dot dot) in the dID parameter.
0
Attacker Value
Unknown
CVE-2017-5645
Disclosure Date: April 17, 2017 (last updated November 08, 2023)
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
0
Attacker Value
Unknown
CVE-2016-8925
Disclosure Date: April 14, 2017 (last updated November 26, 2024)
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could allow a remote attacker to include arbitrary files which could allow the attacker to read any file on the system. IBM X-Force ID: 118538.
0
Attacker Value
Unknown
CVE-2016-8927
Disclosure Date: April 14, 2017 (last updated November 26, 2024)
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118540.
0
Attacker Value
Unknown
CVE-2016-8926
Disclosure Date: April 14, 2017 (last updated November 26, 2024)
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could allow a remote attacker to read system files or data that is restricted to authorized users. IBM X-Force ID: 118539.
0
Attacker Value
Unknown
CVE-2016-7547
Disclosure Date: April 12, 2017 (last updated November 26, 2024)
A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.cgi interface.
0
Attacker Value
Unknown
CVE-2016-7552
Disclosure Date: April 12, 2017 (last updated November 26, 2024)
On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can be used to bypass authentication or cause a DoS.
0
Attacker Value
Unknown
CVE-2016-5840
Disclosure Date: June 30, 2016 (last updated November 25, 2024)
hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to execute arbitrary code via shell metacharacters in the filename parameter of the Content-Disposition header.
0
Attacker Value
Unknown
CVE-2016-4369
Disclosure Date: June 08, 2016 (last updated November 25, 2024)
HPE Discovery and Dependency Mapping Inventory (DDMi) 9.30, 9.31, 9.32, 9.32 update 1, 9.32 update 2, and 9.32 update 3 allows remote authenticated users to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
0