Show filters
287 Total Results
Displaying 151-160 of 287
Sort by:
Attacker Value
Unknown

CVE-2011-2487

Disclosure Date: March 11, 2020 (last updated February 21, 2025)
The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.
Attacker Value
Unknown

CVE-2020-7238

Disclosure Date: January 27, 2020 (last updated February 21, 2025)
Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.
Attacker Value
Unknown

CVE-2012-5663

Disclosure Date: December 30, 2019 (last updated November 27, 2024)
The isearch package (textproc/isearch) before 1.47.01nb1 uses the tempnam() function to create insecure temporary files into a publicly-writable area (/tmp).
Attacker Value
Unknown

CVE-2019-8632

Disclosure Date: December 18, 2019 (last updated November 27, 2024)
Some analytics data was sent using HTTP rather than HTTPS. This was addressed by no longer sending this analytics data. This issue is fixed in Texture 5.11.10 for iOS, Texture 4.22.0.4 for Android. An attacker in a privileged network position may be able to intercept analytics data.
Attacker Value
Unknown

CVE-2015-8980

Disclosure Date: November 04, 2019 (last updated November 27, 2024)
The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code.
Attacker Value
Unknown

CVE-2019-16253

Disclosure Date: September 25, 2019 (last updated November 27, 2024)
The Text-to-speech Engine (aka SamsungTTS) application before 3.0.02.7 and 3.0.00.101 for Android allows a local attacker to escalate privileges, e.g., to system privileges. The Samsung case ID is 101755.
Attacker Value
Unknown

CVE-2019-13187

Disclosure Date: September 05, 2019 (last updated November 27, 2024)
The Rich Text Formatter (Redactor) extension through v1.1.1 for Symphony CMS has an Unauthenticated arbitrary file upload vulnerability in content.fileupload.php and content.imageupload.php.
0
Attacker Value
Unknown

CVE-2019-14439

Disclosure Date: July 30, 2019 (last updated November 08, 2023)
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.
Attacker Value
Unknown

CVE-2019-10249

Disclosure Date: May 06, 2019 (last updated November 27, 2024)
All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artifacts may have been compromised.
Attacker Value
Unknown

CVE-2018-20165

Disclosure Date: March 22, 2019 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in OpenText Portal 7.4.4 allows remote attackers to inject arbitrary web script or HTML via the vgnextoid parameter to a menuitem URI.
0