Show filters
219 Total Results
Displaying 181-190 of 219
Sort by:
Attacker Value
Unknown
CVE-2014-2031
Disclosure Date: March 20, 2018 (last updated November 26, 2024)
Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and crash) by leveraging permission to perform recursive queries against Deadwood, related to a logic error.
0
Attacker Value
Unknown
CVE-2014-2032
Disclosure Date: March 20, 2018 (last updated November 26, 2024)
Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and crash) by leveraging permission to perform recursive queries against Deadwood, related to missing input validation.
0
Attacker Value
Unknown
CVE-2018-8710
Disclosure Date: March 14, 2018 (last updated November 26, 2024)
A remote code execution issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPress, as demonstrated by the shortcode parameter in a woof_redraw_woof action. The plugin implemented a page redraw AJAX function accessible to anyone without any authentication. WordPress shortcode markup in the "shortcode" parameters would be evaluated. Normally unauthenticated users can't evaluate shortcodes as they are often sensitive.
0
Attacker Value
Unknown
CVE-2018-2400
Disclosure Date: March 14, 2018 (last updated November 26, 2024)
Under certain conditions SAP Business Process Automation (BPA) By Redwood, 9.00, 9.10, allows an attacker to access information which would otherwise be restricted.
0
Attacker Value
Unknown
CVE-2018-2366
Disclosure Date: March 14, 2018 (last updated November 26, 2024)
SAP Business Process Automation (BPA) By Redwood, 9.0, 9.1, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs.
0
Attacker Value
Unknown
CVE-2018-8711
Disclosure Date: March 14, 2018 (last updated November 26, 2024)
A local file inclusion issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPress, as demonstrated by the shortcode parameter in a woof_redraw_woof action. The vulnerability is due to the lack of args/input validation on render_html before allowing it to be called by extract(), a PHP built-in function. Because of this, the supplied args/input can be used to overwrite the $pagepath variable, which then could lead to a local file inclusion attack.
0
Attacker Value
Unknown
CVE-2018-2401
Disclosure Date: March 14, 2018 (last updated November 26, 2024)
SAP Business Process Automation (BPA) By Redwood does not sufficiently validate an XML document accepted from an untrusted source resulting in an XML External Entity (XXE) vulnerability.
0
Attacker Value
Unknown
CVE-2018-0544
Disclosure Date: March 09, 2018 (last updated November 26, 2024)
Untrusted search path vulnerability in WinShot 1.53a and earlier (Installer) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
0
Attacker Value
Unknown
CVE-2018-0543
Disclosure Date: March 09, 2018 (last updated November 26, 2024)
Untrusted search path vulnerability in Jtrim 1.53c and earlier (Installer) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
0
Attacker Value
Unknown
CVE-2015-2329
Disclosure Date: February 08, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted order.
0