Show filters
207 Total Results
Displaying 161-170 of 207
Sort by:
Attacker Value
Unknown

CVE-2018-1000837

Disclosure Date: December 20, 2018 (last updated November 27, 2024)
UML Designer version <= 8.0.0 contains a XML External Entity (XXE) vulnerability in XML parser for plugins that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via malicious plugins.xml file.
Attacker Value
Unknown

CVE-2018-18987

Disclosure Date: November 30, 2018 (last updated November 27, 2024)
VT-Designer Version 2.1.7.31 is vulnerable by the program populating objects with user supplied input via a file without first checking for validity, allowing attacker supplied input to be written to known memory locations. This may cause the program to crash or allow remote code execution.
0
Attacker Value
Unknown

CVE-2018-18983

Disclosure Date: November 30, 2018 (last updated November 27, 2024)
VT-Designer Version 2.1.7.31 is vulnerable by the program reading the contents of a file (which is already in memory) into another heap-based buffer, which may cause the program to crash or allow remote code execution.
0
Attacker Value
Unknown

CVE-2018-18695

Disclosure Date: November 01, 2018 (last updated November 27, 2024)
M2SOFT Report Designer Viewer 5.0 allows a Buffer Overflow with Extended Instruction Pointer (EIP) control via a crafted MRD file.
0
Attacker Value
Unknown

Orchestration Designer Runtime Config CSRF

Disclosure Date: September 21, 2018 (last updated November 27, 2024)
A CSRF vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could allow an attacker to add, change, or remove administrative settings. Affected versions of Avaya Aura Orchestration Designer include all versions up to 7.2.1.
0
Attacker Value
Unknown

Orchestration Designer Runtime Config XSS

Disclosure Date: September 21, 2018 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could result in malicious content being returned to the user. Affected versions of Avaya Aura Orchestration Designer include all versions up to 7.2.1.
0
Attacker Value
Unknown

CVE-2018-13806

Disclosure Date: September 12, 2018 (last updated November 27, 2024)
A vulnerability has been identified in SIEMENS TD Keypad Designer (All versions). A DLL hijacking vulnerability exists in all versions of SIEMENS TD Keypad Designer which could allow an attacker to execute code with the permission of the user running TD Designer. The attacker must have write access to the directory containing the TD project file in order to exploit the vulnerability. A legitimate user with higher privileges than the attacker must open the TD project in order for this vulnerability to be exploited. At the time of advisory publication no public exploitation of this security vulnerability was known.
0
Attacker Value
Unknown

CVE-2018-8833

Disclosure Date: April 25, 2018 (last updated November 26, 2024)
Heap-based buffer overflow vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allow remote code execution.
Attacker Value
Unknown

CVE-2018-8837

Disclosure Date: April 25, 2018 (last updated November 26, 2024)
Processing specially crafted .pm3 files in Advantech WebAccess HMI Designer 2.1.7.32 and prior may cause the system to write outside the intended buffer area and may allow remote code execution.
0
Attacker Value
Unknown

CVE-2018-8835

Disclosure Date: April 25, 2018 (last updated November 26, 2024)
Double free vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allow remote code execution.
0