Show filters
234 Total Results
Displaying 151-160 of 234
Sort by:
Attacker Value
Unknown
CVE-2019-12419
Disclosure Date: November 06, 2019 (last updated November 08, 2023)
Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to somehow steal an authorization code issued to another client, then they could exploit this vulnerability to obtain an access token for the other client.
0
Attacker Value
Unknown
CVE-2019-12406
Disclosure Date: November 06, 2019 (last updated November 08, 2023)
Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a very large number of message attachments. From the 3.3.4 and 3.2.11 releases, a default limit of 50 message attachments is enforced. This is configurable via the message property "attachment-max-count".
0
Attacker Value
Unknown
CVE-2010-4178
Disclosure Date: November 06, 2019 (last updated November 27, 2024)
MySQL-GUI-tools (mysql-administrator) leaks passwords into process list after with launch of mysql text console
0
Attacker Value
Unknown
CVE-2019-18192
Disclosure Date: October 17, 2019 (last updated November 27, 2024)
GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable, a similar issue to CVE-2019-17365.
0
Attacker Value
Unknown
CVE-2019-19329
Disclosure Date: July 06, 2019 (last updated November 27, 2024)
In Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07, when mathematical expressions in results are displayed directly, arbitrary JavaScript execution can occur, aka XSS. This was addressed by introducing MathJax as a new mathematics rendering engine. NOTE: this GUI code is no longer bundled with the Wikibase Wikidata Query Service snapshots, such as 0.3.6-SNAPSHOT.
0
Attacker Value
Unknown
CVE-2019-11117
Disclosure Date: June 13, 2019 (last updated November 27, 2024)
Improper permissions in the installer for Intel(R) Omni-Path Fabric Manager GUI before version 10.9.2.1.1 may allow an authenticated user to potentially enable escalation of privilege via local attack.
0
Attacker Value
Unknown
CVE-2019-9891
Disclosure Date: May 31, 2019 (last updated November 27, 2024)
The function getopt_simple as described in Advanced Bash Scripting Guide (ISBN 978-1435752184) allows privilege escalation and execution of commands when used in a shell script called, for example, via sudo.
0
Attacker Value
Unknown
CVE-2018-7815
Disclosure Date: February 06, 2019 (last updated November 27, 2024)
A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) on c3core.dll which could cause remote code to be executed when parsing a GD1 file
0
Attacker Value
Unknown
CVE-2018-7814
Disclosure Date: February 06, 2019 (last updated November 27, 2024)
A Stack-based Buffer Overflow (CWE-121) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) which could cause remote code to be executed when parsing a GD1 file
0
Attacker Value
Unknown
CVE-2018-7813
Disclosure Date: February 06, 2019 (last updated November 27, 2024)
A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) on pcwin.dll which could cause remote code to be executed when parsing a GD1 file
0