Show filters
284 Total Results
Displaying 121-130 of 284
Sort by:
Attacker Value
Unknown
CVE-2019-4406
Disclosure Date: November 25, 2019 (last updated November 27, 2024)
IBM Spectrum Protect Backup-Archive Client 7.1 and 8.1 may be vulnerable to a denial of service attack due to a timing issue between client and server TCP/IP communications. IBM X-Force ID: 162477.
0
Attacker Value
Unknown
CVE-2019-19221
Disclosure Date: November 21, 2019 (last updated November 08, 2023)
In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.
0
Attacker Value
Unknown
CVE-2006-4245
Disclosure Date: November 06, 2019 (last updated November 27, 2024)
archivemail 0.6.2 uses temporary files insecurely leading to a possible race condition.
0
Attacker Value
Unknown
CVE-2019-10743
Disclosure Date: October 29, 2019 (last updated November 08, 2023)
All versions of archiver allow attacker to perform a Zip Slip attack via the "unarchive" functions. It is exploited using a specially crafted zip archive, that holds path traversal filenames. When exploited, a filename in a malicious archive is concatenated to the target extraction directory, which results in the final path ending up outside of the target folder. For instance, a zip may hold a file with a "../../file.exe" location and thus break out of the target folder. If an executable or a configuration file is overwritten with a file containing malicious code, the problem can turn into an arbitrary code execution issue quite easily.
0
Attacker Value
Unknown
CVE-2019-18408
Disclosure Date: October 24, 2019 (last updated November 08, 2023)
archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol.
0
Attacker Value
Unknown
CVE-2017-18376
Disclosure Date: June 02, 2019 (last updated November 27, 2024)
An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write access to escalate their privileges to the administrator's privileges. This affects app/controllers/UserCtrl.scala.
0
Attacker Value
Unknown
CVE-2019-10685
Disclosure Date: May 24, 2019 (last updated November 08, 2023)
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Heidelberg Prinect Archiver v2013 release 1.0.
0
Attacker Value
Unknown
CVE-2019-11463
Disclosure Date: April 23, 2019 (last updated November 27, 2024)
A memory leak in archive_read_format_zip_cleanup in archive_read_support_format_zip.c in libarchive 3.3.4-dev allows remote attackers to cause a denial of service via a crafted ZIP file because of a HAVE_LZMA_H typo. NOTE: this only affects users who downloaded the development code from GitHub. Users of the product's official releases are unaffected.
0
Attacker Value
Unknown
CVE-2018-1882
Disclosure Date: April 08, 2019 (last updated November 27, 2024)
In a certain atypical IBM Spectrum Protect 7.1 and 8.1 configurations, the node password could be displayed in plain text in the IBM Spectrum Protect client trace file. IBM X-Force ID: 151968.
0
Attacker Value
Unknown
CVE-2018-1853
Disclosure Date: April 08, 2019 (last updated November 27, 2024)
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 151014.
0