Show filters
237 Total Results
Displaying 131-140 of 237
Sort by:
Attacker Value
Unknown
CVE-2019-15685
Disclosure Date: November 26, 2019 (last updated November 27, 2024)
Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component allowed an attacker remotely disable such product's security features as private browsing and anti-banner. Bypass.
0
Attacker Value
Unknown
CVE-2019-15688
Disclosure Date: November 26, 2019 (last updated November 27, 2024)
Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component did not adequately inform the user about the threat of redirecting to an untrusted site. Bypass.
0
Attacker Value
Unknown
CVE-2012-6078
Disclosure Date: November 22, 2019 (last updated November 27, 2024)
W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.
0
Attacker Value
Unknown
CVE-2012-6077
Disclosure Date: November 22, 2019 (last updated November 27, 2024)
W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files.
0
Attacker Value
Unknown
CVE-2012-6079
Disclosure Date: November 22, 2019 (last updated November 27, 2024)
W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via their hash keys.
0
Attacker Value
Unknown
Implicit loading of DLLs
Disclosure Date: November 13, 2019 (last updated November 08, 2023)
A Privilege Escalation vulnerability in the Microsoft Windows client in McAfee Total Protection 16.0.R22 and earlier allows administrators to execute arbitrary code via carefully placing malicious files in specific locations protected by administrator permission.
0
Attacker Value
Unknown
CVE-2019-16897
Disclosure Date: October 28, 2019 (last updated November 27, 2024)
In K7 Antivirus Premium 16.0.xxx through 16.0.0120; K7 Total Security 16.0.xxx through 16.0.0120; and K7 Ultimate Security 16.0.xxx through 16.0.0120, the module K7TSHlpr.dll improperly validates the administrative privileges of the user, allowing arbitrary registry writes in the K7AVOptn.dll module to facilitate escalation of privileges via inter-process communication with a service process.
0
Attacker Value
Unknown
File masquerade attack vulnerability in McAfee Total Protection
Disclosure Date: October 28, 2019 (last updated November 08, 2023)
A File Masquerade vulnerability in McAfee Total Protection (MTP) version 16.0.R21 and earlier in Windows client allowed an attacker to read the plaintext list of AV-Scan exclusion files from the Windows registry, and to possibly replace excluded files with potential malware without being detected.
0
Attacker Value
Unknown
McAfee Total Protection - Free Antivirus Trial: DLL Search Order Hijacking vuln…
Disclosure Date: September 13, 2019 (last updated November 08, 2023)
DLL Search Order Hijacking vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Free Antivirus Trial 16.0.R18 and earlier allows local users to execute arbitrary code via execution from a compromised folder placed by an attacker with administrator rights.
0
Attacker Value
Unknown
CVE-2019-15954
Disclosure Date: September 05, 2019 (last updated November 27, 2024)
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a malicious widget with a special tag containing JavaScript code that will be evaluated server side. In the process of evaluating the tag by the back-end, it is possible to escape the sandbox object by using the following payload: <script total>global.process.mainModule.require(child_process).exec(RCE);</script>
0