Show filters
234 Total Results
Displaying 161-170 of 234
Sort by:
Attacker Value
Unknown

CVE-2018-7652

Disclosure Date: March 04, 2018 (last updated November 26, 2024)
lib/Zonemaster/GUI/Dancer/Export.pm in Zonemaster Web GUI before 1.0.11 has XSS.
Attacker Value
Unknown

CVE-2017-1000455

Disclosure Date: January 02, 2018 (last updated November 26, 2024)
GuixSD prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d used POSIX hard links incorrectly, leading the creation of setuid executables in "the store", violating a fundamental security assumption of GNU Guix.
0
Attacker Value
Unknown

CVE-2017-14001

Disclosure Date: September 26, 2017 (last updated November 26, 2024)
An Improper Neutralization of Special Elements used in an OS Command issue was discovered in Digium Asterisk GUI 2.1.0 and prior. An OS command injection vulnerability has been identified that may allow the execution of arbitrary code on the system through the inclusion of OS commands in the URL request of the program.
0
Attacker Value
Unknown

CVE-2017-6950

Disclosure Date: March 23, 2017 (last updated November 26, 2024)
SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAP code, aka SAP Security Note 2407616.
0
Attacker Value
Unknown

CVE-2016-8606

Disclosure Date: January 12, 2017 (last updated November 08, 2023)
The REPL server (--listen) in GNU Guile 2.0.12 allows an attacker to execute arbitrary code via an HTTP inter-protocol attack.
0
Attacker Value
Unknown

CVE-2016-8605

Disclosure Date: January 12, 2017 (last updated November 08, 2023)
The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threads could end up creating files with insecure permissions. For example, mkdir without the optional mode argument would create directories as 0777. This is fixed in Guile 2.0.13. Prior versions are affected.
0
Attacker Value
Unknown

CVE-2016-5482

Disclosure Date: October 25, 2016 (last updated November 25, 2024)
Unspecified vulnerability in the Oracle Commerce Guided Search component in Oracle Commerce 6.2.2, 6.3.0, 6.4.1.2, and 6.5.0 through 6.5.2 allows remote attackers to affect confidentiality and integrity via unknown vectors.
0
Attacker Value
Unknown

CVE-2015-2282

Disclosure Date: June 02, 2015 (last updated October 05, 2023)
Stack-based buffer overflow in the LZC decompression implementation (CsObjectInt::CsDecomprLZC function in vpa106cslzc.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver RFC SDK, GUI, RFC SDK, SAPCAR archive tool, and other products allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, aka SAP Security Note 2124806, 2121661, 2127995, and 2125316.
0
Attacker Value
Unknown

CVE-2015-2278

Disclosure Date: June 02, 2015 (last updated October 05, 2023)
The LZH decompression implementation (CsObjectInt::BuildHufTree function in vpa108csulzh.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver RFC SDK, GUI, RFC SDK, SAPCAR archive tool, and other products allows context-dependent attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, related to look-ups of non-simple codes, aka SAP Security Note 2124806, 2121661, 2127995, and 2125316.
0
Attacker Value
Unknown

CVE-2015-0495

Disclosure Date: April 16, 2015 (last updated October 05, 2023)
Unspecified vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component in Oracle Commerce Platform 3.x and 11.x allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Workbench.
0