Show filters
234 Total Results
Displaying 151-160 of 234
Sort by:
Attacker Value
Unknown

CVE-2019-12419

Disclosure Date: November 06, 2019 (last updated November 08, 2023)
Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to somehow steal an authorization code issued to another client, then they could exploit this vulnerability to obtain an access token for the other client.
Attacker Value
Unknown

CVE-2019-12406

Disclosure Date: November 06, 2019 (last updated November 08, 2023)
Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a very large number of message attachments. From the 3.3.4 and 3.2.11 releases, a default limit of 50 message attachments is enforced. This is configurable via the message property "attachment-max-count".
Attacker Value
Unknown

CVE-2010-4178

Disclosure Date: November 06, 2019 (last updated November 27, 2024)
MySQL-GUI-tools (mysql-administrator) leaks passwords into process list after with launch of mysql text console
Attacker Value
Unknown

CVE-2019-18192

Disclosure Date: October 17, 2019 (last updated November 27, 2024)
GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable, a similar issue to CVE-2019-17365.
Attacker Value
Unknown

CVE-2019-19329

Disclosure Date: July 06, 2019 (last updated November 27, 2024)
In Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07, when mathematical expressions in results are displayed directly, arbitrary JavaScript execution can occur, aka XSS. This was addressed by introducing MathJax as a new mathematics rendering engine. NOTE: this GUI code is no longer bundled with the Wikibase Wikidata Query Service snapshots, such as 0.3.6-SNAPSHOT.
Attacker Value
Unknown

CVE-2019-11117

Disclosure Date: June 13, 2019 (last updated November 27, 2024)
Improper permissions in the installer for Intel(R) Omni-Path Fabric Manager GUI before version 10.9.2.1.1 may allow an authenticated user to potentially enable escalation of privilege via local attack.
Attacker Value
Unknown

CVE-2019-9891

Disclosure Date: May 31, 2019 (last updated November 27, 2024)
The function getopt_simple as described in Advanced Bash Scripting Guide (ISBN 978-1435752184) allows privilege escalation and execution of commands when used in a shell script called, for example, via sudo.
0
Attacker Value
Unknown

CVE-2018-7815

Disclosure Date: February 06, 2019 (last updated November 27, 2024)
A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) on c3core.dll which could cause remote code to be executed when parsing a GD1 file
0
Attacker Value
Unknown

CVE-2018-7814

Disclosure Date: February 06, 2019 (last updated November 27, 2024)
A Stack-based Buffer Overflow (CWE-121) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) which could cause remote code to be executed when parsing a GD1 file
0
Attacker Value
Unknown

CVE-2018-7813

Disclosure Date: February 06, 2019 (last updated November 27, 2024)
A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) on pcwin.dll which could cause remote code to be executed when parsing a GD1 file
0