Show filters
1,199 Total Results
Displaying 21-30 of 1,199
Sort by:
Attacker Value
Unknown

CVE-2017-12617

Disclosure Date: October 04, 2017 (last updated July 17, 2024)
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
Attacker Value
Unknown

CVE-2015-7547

Disclosure Date: February 18, 2016 (last updated November 25, 2024)
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.
1
Attacker Value
Unknown

CVE-2009-0217

Disclosure Date: July 14, 2009 (last updated October 04, 2023)
The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.
1
Attacker Value
Unknown

CVE-2025-24849

Disclosure Date: February 28, 2025 (last updated March 01, 2025)
Lack of encryption in transit for cloud infrastructure facilitating potential for sensitive data manipulation or exposure.
0
Attacker Value
Unknown

CVE-2025-24843

Disclosure Date: February 28, 2025 (last updated March 01, 2025)
Insecure file retrieval process that facilitates potential for file manipulation to affect product stability and confidentiality, integrity, authenticity, and attestation of stored data.
0
Attacker Value
Unknown

CVE-2025-24318

Disclosure Date: February 28, 2025 (last updated March 01, 2025)
Cookie policy is observable via built-in browser tools. In the presence of XSS, this could lead to full session compromise.
0
Attacker Value
Unknown

CVE-2025-24316

Disclosure Date: February 28, 2025 (last updated March 01, 2025)
The Dario Health Internet-based server infrastructure is vulnerable due to exposure of development environment details, which could lead to unsafe functionality.
0
Attacker Value
Unknown

CVE-2025-23405

Disclosure Date: February 28, 2025 (last updated March 01, 2025)
Unauthenticated log effects metrics gathering incident response efforts and potentially exposes risk of injection attacks (ex log injection).
0
Attacker Value
Unknown

CVE-2025-20060

Disclosure Date: February 28, 2025 (last updated March 01, 2025)
An attacker could expose cross-user personal identifiable information (PII) and personal health information transmitted to the Android device via the Dario Health application database.
0
Attacker Value
Unknown

CVE-2025-20049

Disclosure Date: February 28, 2025 (last updated March 01, 2025)
The Dario Health portal service application is vulnerable to XSS, which could allow an attacker to obtain sensitive information.
0