Show filters
596 Total Results
Displaying 181-190 of 596
Sort by:
Attacker Value
Unknown
CVE-2019-17135
Disclosure Date: February 08, 2020 (last updated February 21, 2025)
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-8775.
0
Attacker Value
Unknown
CVE-2020-6059
Disclosure Date: February 04, 2020 (last updated February 21, 2025)
An exploitable out of bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A specially crafted SNMP request can trigger an out of bounds memory read which can result in sensitive information disclosure and Denial Of Service. In order to trigger this vulnerability, an attacker needs to send a specially crafted packet to the vulnerable server.
0
Attacker Value
Unknown
CVE-2020-6058
Disclosure Date: February 04, 2020 (last updated February 21, 2025)
An exploitable out-of-bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A specially crafted SNMP request can trigger an out-of-bounds memory read, which can result in the disclosure of sensitive information and denial of service. To trigger this vulnerability, an attacker needs to send a specially crafted packet to the vulnerable server.
0
Attacker Value
Unknown
CVE-2020-6060
Disclosure Date: February 04, 2020 (last updated February 21, 2025)
A stack buffer overflow vulnerability exists in the way MiniSNMPD version 1.4 handles multiple connections. A specially timed sequence of SNMP connections can trigger a stack overflow, resulting in a denial of service. To trigger this vulnerability, an attacker needs to simply initiate multiple connections to the server.
0
Attacker Value
Unknown
CVE-2019-5130
Disclosure Date: January 16, 2020 (last updated February 21, 2025)
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.7.0.29435. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
0
Attacker Value
Unknown
CVE-2019-5145
Disclosure Date: January 16, 2020 (last updated February 21, 2025)
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit PDF Reader, version 9.7.0.29435. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
0
Attacker Value
Unknown
CVE-2019-5126
Disclosure Date: January 16, 2020 (last updated February 21, 2025)
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit PDF Reader, version 9.7.0.29435. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
0
Attacker Value
Unknown
CVE-2019-5131
Disclosure Date: January 16, 2020 (last updated February 21, 2025)
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, version 9.7.0.29435. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
0
Attacker Value
Unknown
CVE-2014-5013
Disclosure Date: January 10, 2020 (last updated November 28, 2024)
DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383.
0
Attacker Value
Unknown
CVE-2014-5012
Disclosure Date: January 10, 2020 (last updated November 28, 2024)
DOMPDF before 0.6.2 allows denial of service.
0