Show filters
207 Total Results
Displaying 161-170 of 207
Sort by:
Attacker Value
Unknown
CVE-2018-1000837
Disclosure Date: December 20, 2018 (last updated November 27, 2024)
UML Designer version <= 8.0.0 contains a XML External Entity (XXE) vulnerability in XML parser for plugins that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via malicious plugins.xml file.
0
Attacker Value
Unknown
CVE-2018-18987
Disclosure Date: November 30, 2018 (last updated November 27, 2024)
VT-Designer Version 2.1.7.31 is vulnerable by the program populating objects with user supplied input via a file without first checking for validity, allowing attacker supplied input to be written to known memory locations. This may cause the program to crash or allow remote code execution.
0
Attacker Value
Unknown
CVE-2018-18983
Disclosure Date: November 30, 2018 (last updated November 27, 2024)
VT-Designer Version 2.1.7.31 is vulnerable by the program reading the contents of a file (which is already in memory) into another heap-based buffer, which may cause the program to crash or allow remote code execution.
0
Attacker Value
Unknown
CVE-2018-18695
Disclosure Date: November 01, 2018 (last updated November 27, 2024)
M2SOFT Report Designer Viewer 5.0 allows a Buffer Overflow with Extended Instruction Pointer (EIP) control via a crafted MRD file.
0
Attacker Value
Unknown
Orchestration Designer Runtime Config CSRF
Disclosure Date: September 21, 2018 (last updated November 27, 2024)
A CSRF vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could allow an attacker to add, change, or remove administrative settings. Affected versions of Avaya Aura Orchestration Designer include all versions up to 7.2.1.
0
Attacker Value
Unknown
Orchestration Designer Runtime Config XSS
Disclosure Date: September 21, 2018 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could result in malicious content being returned to the user. Affected versions of Avaya Aura Orchestration Designer include all versions up to 7.2.1.
0
Attacker Value
Unknown
CVE-2018-13806
Disclosure Date: September 12, 2018 (last updated November 27, 2024)
A vulnerability has been identified in SIEMENS TD Keypad Designer (All versions). A DLL hijacking vulnerability exists in all versions of SIEMENS TD Keypad Designer which could allow an attacker to execute code with the permission of the user running TD Designer. The attacker must have write access to the directory containing the TD project file in order to exploit the vulnerability. A legitimate user with higher privileges than the attacker must open the TD project in order for this vulnerability to be exploited. At the time of advisory publication no public exploitation of this security vulnerability was known.
0
Attacker Value
Unknown
CVE-2018-8833
Disclosure Date: April 25, 2018 (last updated November 26, 2024)
Heap-based buffer overflow vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allow remote code execution.
0
Attacker Value
Unknown
CVE-2018-8837
Disclosure Date: April 25, 2018 (last updated November 26, 2024)
Processing specially crafted .pm3 files in Advantech WebAccess HMI Designer 2.1.7.32 and prior may cause the system to write outside the intended buffer area and may allow remote code execution.
0
Attacker Value
Unknown
CVE-2018-8835
Disclosure Date: April 25, 2018 (last updated November 26, 2024)
Double free vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allow remote code execution.
0