Show filters
70 Total Results
Displaying 21-30 of 70
Sort by:
Attacker Value
Unknown

CVE-2019-6008

Disclosure Date: December 26, 2019 (last updated November 27, 2024)
An unquoted search path vulnerability in Multiple Yokogawa products for Windows (Exaopc (R1.01.00 ? R3.77.00), Exaplog (R1.10.00 ? R3.40.00), Exaquantum (R1.10.00 ? R3.02.00 and R3.15.00), Exaquantum/Batch (R1.01.00 ? R2.50.40), Exasmoc (all revisions), Exarqe (all revisions), GA10 (R1.01.01 ? R3.05.01), and InsightSuiteAE (R1.01.00 ? R1.06.00)) allow local users to gain privileges via a Trojan horse executable file and execute arbitrary code with eleveted privileges.
Attacker Value
Unknown

CVE-2019-17579

Disclosure Date: October 14, 2019 (last updated November 27, 2024)
SonarSource SonarQube before 7.8 has XSS in project links on account/projects.
Attacker Value
Unknown

CVE-2018-1000425

Disclosure Date: January 09, 2019 (last updated November 27, 2024)
An insufficiently protected credentials vulnerability exists in Jenkins SonarQube Scanner Plugin 2.8 and earlier in SonarInstallation.java that allows attackers with local file system access to obtain the credentials used to connect to SonarQube.
0
Attacker Value
Unknown

CVE-2018-19413

Disclosure Date: December 14, 2018 (last updated November 27, 2024)
A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive information such as valid user-account logins in the web application. The vulnerability occurs because of improperly configured access controls that cause the API to return the externalIdentity field to non-administrator users. The attacker could use this information in subsequent attacks against the system.
0
Attacker Value
Unknown

CVE-2016-2922

Disclosure Date: August 13, 2018 (last updated November 27, 2024)
IBM Rational ClearQuest 8.0 through 8.0.1.9 and 9.0 through 9.0.1.3 (CQ OSLC linkages, EmailRelay) fails to check the SSL certificate against the requested hostname. It is subject to a man-in-the-middle attack with an impersonating server observing all the data transmitted to the real server. IBM X-Force ID: 113353.
0
Attacker Value
Unknown

CVE-2014-0950

Disclosure Date: April 20, 2018 (last updated November 26, 2024)
Multiple XML external entity (XXE) vulnerabilities in (1) CQWeb / CM Server, (2) ClearQuest Native client, (3) ClearQuest Eclipse client, and (4) ClearQuest Eclipse Designer components in IBM Rational ClearQuest 7.1.1 through 7.1.1.9, 7.1.2 through 7.1.2.13, 8.0.0 through 8.0.0.10, and 8.0.1 through 8.0.1.3 allow remote attackers to cause a denial of service or access other servers via crafted XML data. IBM X-Force ID: 92623.
0
Attacker Value
Unknown

CVE-2017-16945

Disclosure Date: January 31, 2018 (last updated November 26, 2024)
The standardrestorer binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently gain root privileges via a crafted restore path.
0
Attacker Value
Unknown

CVE-2017-16928

Disclosure Date: January 31, 2018 (last updated November 26, 2024)
The arq_updater binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently gain root privileges via a crafted update URL, as demonstrated by file:///tmp/blah/Arq.zip.
0
Attacker Value
Unknown

CVE-2017-16895

Disclosure Date: December 01, 2017 (last updated November 26, 2024)
The (1) arq_updater, (2) arqcommitter, (3) standardrestorer, (4) arqglacierrestorer, and (5) arqs3glacierrestorer helper apps in Arq 5.x before 5.10 for Mac allow local users to gain root privileges via a crafted data packet.
Attacker Value
Unknown

CVE-2017-15357

Disclosure Date: December 01, 2017 (last updated November 26, 2024)
The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges via a symlink attack on the updater binary itself.
0