Show filters
165 Total Results
Displaying 131-140 of 165
Sort by:
Attacker Value
Unknown

CVE-2016-7072

Disclosure Date: September 10, 2018 (last updated November 27, 2024)
An issue has been found in PowerDNS Authoritative Server before 3.4.11 and 4.0.2 allowing a remote, unauthenticated attacker to cause a denial of service by opening a large number of TCP connections to the web server. If the web server runs out of file descriptors, it triggers an exception and terminates the whole PowerDNS process. While it's more complicated for an unauthorized attacker to make the web server run out of file descriptors since its connection will be closed just after being accepted, it might still be possible.
0
Attacker Value
Unknown

CVE-2018-0429

Disclosure Date: August 09, 2018 (last updated November 27, 2024)
Stack-based buffer overflow in the Cisco Thor decoder before commit 18de8f9f0762c3a542b1122589edb8af859d9813 allows local users to cause a denial of service (segmentation fault) and execute arbitrary code via a crafted non-conformant Thor bitstream.
0
Attacker Value
Unknown

CVE-2018-2440

Disclosure Date: July 10, 2018 (last updated November 27, 2024)
Under certain circumstances SAP Dynamic Authorization Management (DAM) by NextLabs (Java Policy Controller versions 7.7 and 8.5) exposes sensitive information in the application logs.
0
Attacker Value
Unknown

CVE-2018-7534

Disclosure Date: May 30, 2018 (last updated November 26, 2024)
In Stealth Authorization Server before 3.3.017.0 in Unisys Stealth Solution, an encryption key may be left in memory.
0
Attacker Value
Unknown

CVE-2017-15091

Disclosure Date: January 23, 2018 (last updated November 26, 2024)
An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4.0.4 and 3.x up to and including 3.4.11, where some operations that have an impact on the state of the server are still allowed even though the API has been configured as read-only via the api-readonly keyword. This missing check allows an attacker with valid API credentials to flush the cache, trigger a zone transfer or send a NOTIFY.
0
Attacker Value
Unknown

CVE-2017-1000090

Disclosure Date: October 05, 2017 (last updated November 26, 2024)
Role-based Authorization Strategy Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks. This allowed attackers to add administrator role to any user, or to remove the authorization configuration, preventing legitimate access to Jenkins.
0
Attacker Value
Unknown

CVE-2016-6172

Disclosure Date: September 26, 2016 (last updated November 25, 2024)
PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a denial of service (memory exhaustion and secondary DNS server crash) via a large (1) AXFR or (2) IXFR response.
0
Attacker Value
Unknown

CVE-2016-5426

Disclosure Date: September 21, 2016 (last updated November 25, 2024)
PowerDNS (aka pdns) Authoritative Server before 3.4.10 allows remote attackers to cause a denial of service (backend CPU consumption) via a long qname.
0
Attacker Value
Unknown

CVE-2016-5427

Disclosure Date: September 21, 2016 (last updated November 25, 2024)
PowerDNS (aka pdns) Authoritative Server before 3.4.10 does not properly handle a . (dot) inside labels, which allows remote attackers to cause a denial of service (backend CPU consumption) via a crafted DNS query.
0
Attacker Value
Unknown

CVE-2016-1789

Disclosure Date: April 05, 2016 (last updated November 25, 2024)
Apple iBooks Author before 2.4.1 allows remote attackers to read arbitrary files via an iBooks Author file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
0