Show filters
200 Total Results
Displaying 131-140 of 200
Sort by:
Attacker Value
Unknown
CVE-2017-1508
Disclosure Date: September 13, 2017 (last updated November 26, 2024)
IBM Informix Dynamic Server 12.1 could allow a local user logged in with database administrator user to gain root privileges. IBM X-Force ID: 129620.
0
Attacker Value
Unknown
CVE-2017-1310
Disclosure Date: June 29, 2017 (last updated November 26, 2024)
IBM Informix Dynamic Server 12.1 could allow an authenticated user to cause a buffer overflow that would write large assertion fail files to the server. Done enough times, this could use large parts of the file system and cause the server to crash. IBM X-Force ID: 125569.
0
Attacker Value
Unknown
CVE-2017-3743
Disclosure Date: June 20, 2017 (last updated November 26, 2024)
If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utility (ASU), UpdateXpress System Pack Installer (UXSPI) or Dynamic System Analysis (DSA) to a second machine, the other users may be able to see the user ID and clear text password that were used to access the second machine during the time the command is processing.
0
Attacker Value
Unknown
CVE-2016-0226
Disclosure Date: March 28, 2016 (last updated November 25, 2024)
The client implementation in IBM Informix Dynamic Server 11.70.xCn on Windows does not properly restrict access to the (1) nsrd, (2) nsrexecd, and (3) portmap executable files, which allows local users to gain privileges via a Trojan horse file.
0
Attacker Value
Unknown
CVE-2015-5491
Disclosure Date: August 18, 2015 (last updated October 05, 2023)
The Dynamic display block module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users to bypass intended access restrictions and read sensitive titles by leveraging the "administer ddblock" permission.
0
Attacker Value
Unknown
CVE-2013-7192
Disclosure Date: December 21, 2013 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in Dynamic Biz Website Builder (QuickWeb) allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/news-events/newdetail.asp, or the (2) UserID or (3) Password to login.asp.
0
Attacker Value
Unknown
CVE-2012-4857
Disclosure Date: December 08, 2012 (last updated October 05, 2023)
Buffer overflow in IBM Informix 11.50 through 11.50.xC9W2 and 11.70 before 11.70.xC7 allows remote authenticated users to execute arbitrary code via a crafted SQL statement.
0
Attacker Value
Unknown
CVE-2012-3334
Disclosure Date: September 25, 2012 (last updated October 05, 2023)
Stack-based buffer overflow in IBM Informix Dynamic Server (IDS) 11.50 before 11.50.xC9W2 and 11.70 before 11.70.xC5 allows remote authenticated users to execute arbitrary code via crafted arguments in a SET COLLATION statement.
0
Attacker Value
Unknown
CVE-2012-0791
Disclosure Date: January 24, 2012 (last updated November 08, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP before 5.0.18 and Horde Groupware Webmail Edition before 4.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) composeCache, (2) rtemode, or (3) filename_* parameters to the compose page; (4) formname parameter to the contacts popup window; or (5) IMAP mailbox names. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2011-0547
Disclosure Date: August 19, 2011 (last updated October 04, 2023)
Multiple integer overflows in vxsvc.exe in the Veritas Enterprise Administrator service in Symantec Veritas Storage Foundation 5.1 and earlier, Veritas Storage Foundation Cluster File System (SFCFS) 5.1 and earlier, Veritas Storage Foundation Cluster File System Enterprise for Oracle RAC (SFCFSORAC) 5.1 and earlier, Veritas Dynamic Multi-Pathing (DMP) 5.1, and NetBackup PureDisk 6.5.x through 6.6.1.x allow remote attackers to execute arbitrary code via (1) a crafted Unicode string, related to the vxveautil.value_binary_unpack function; (2) a crafted ASCII string, related to the vxveautil.value_binary_unpack function; or (3) a crafted value, related to the vxveautil.kv_binary_unpack function, leading to a buffer overflow.
0