Show filters
284 Total Results
Displaying 151-160 of 284
Sort by:
Attacker Value
Unknown
CVE-2016-8365
Disclosure Date: April 03, 2018 (last updated November 26, 2024)
OSIsoft PI System software (Applications using PI Asset Framework (AF) Client versions prior to PI AF Client 2016, Version 2.8.0; Applications using PI Software Development Kit (SDK) versions prior to PI SDK 2016, Version 1.4.6; PI Buffer Subsystem, versions prior to and including, Version 4.4; and PI Data Archive versions prior to PI Data Archive 2015, Version 3.4.395.64) operates between endpoints without a complete model of endpoint features potentially causing the product to perform actions based on this incomplete model, which could result in a denial of service. OSIsoft reports that in order to exploit the vulnerability an attacker would need to be locally connected to a server. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H)
0
Attacker Value
Unknown
CVE-2018-7529
Disclosure Date: March 14, 2018 (last updated November 26, 2024)
A Deserialization of Untrusted Data issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Unauthenticated users may modify deserialized data to send custom requests that crash the server.
0
Attacker Value
Unknown
CVE-2018-7531
Disclosure Date: March 14, 2018 (last updated November 26, 2024)
An Improper Input Validation issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Unauthenticated users may use unvalidated custom requests to crash the server.
0
Attacker Value
Unknown
CVE-2018-7533
Disclosure Date: March 14, 2018 (last updated November 26, 2024)
An Incorrect Default Permissions issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Insecure default configuration may allow escalation of privileges that gives the actor full control over the system.
0
Attacker Value
Unknown
CVE-2018-1000130
Disclosure Date: March 14, 2018 (last updated November 26, 2024)
A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.
0
Attacker Value
Unknown
CVE-2018-6465
Disclosure Date: January 31, 2018 (last updated November 26, 2024)
The PropertyHive plugin before 1.4.15 for WordPress has XSS via the body parameter to includes/admin/views/html-preview-applicant-matches-email.php.
0
Attacker Value
Unknown
CVE-2017-12625
Disclosure Date: November 01, 2017 (last updated November 26, 2024)
Apache Hive 2.1.x before 2.1.2, 2.2.x before 2.2.1, and 2.3.x before 2.3.1 expose an interface through which masking policies can be defined on tables or views, e.g., using Apache Ranger. When a view is created over a given table, the policy enforcement does not happen correctly on the table for masked columns.
0
Attacker Value
Unknown
CVE-2017-14503
Disclosure Date: September 17, 2017 (last updated November 26, 2024)
libarchive 3.3.2 suffers from an out-of-bounds read within lha_read_data_none() in archive_read_support_format_lha.c when extracting a specially crafted lha archive, related to lha_crc16.
0
Attacker Value
Unknown
CVE-2017-14502
Disclosure Date: September 17, 2017 (last updated November 26, 2024)
read_header in archive_read_support_format_rar.c in libarchive 3.3.2 suffers from an off-by-one error for UTF-16 names in RAR archives, leading to an out-of-bounds read in archive_read_format_rar_read_header.
0
Attacker Value
Unknown
CVE-2017-14501
Disclosure Date: September 17, 2017 (last updated November 26, 2024)
An out-of-bounds read flaw exists in parse_file_info in archive_read_support_format_iso9660.c in libarchive 3.3.2 when extracting a specially crafted iso9660 iso file, related to archive_read_format_iso9660_read_header.
0