Show filters
28 Total Results
Displaying 21-28 of 28
Sort by:
Attacker Value
Unknown

CVE-2022-40638

Disclosure Date: September 15, 2022 (last updated February 24, 2025)
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17102.
Attacker Value
Unknown

CVE-2022-40637

Disclosure Date: September 15, 2022 (last updated February 24, 2025)
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17045.
Attacker Value
Unknown

CVE-2022-40636

Disclosure Date: September 15, 2022 (last updated February 24, 2025)
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17044.
Attacker Value
Unknown

CVE-2021-21620

Disclosure Date: February 24, 2021 (last updated February 22, 2025)
A cross-site request forgery (CSRF) vulnerability in Jenkins Claim Plugin 2.18.1 and earlier allows attackers to change claims.
Attacker Value
Unknown

CVE-2021-21619

Disclosure Date: February 24, 2021 (last updated February 22, 2025)
Jenkins Claim Plugin 2.18.1 and earlier does not escape the user display name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers who are able to control the display names of Jenkins users, either via the security realm, or directly inside Jenkins.
Attacker Value
Unknown

CVE-2019-15536

Disclosure Date: August 23, 2019 (last updated November 27, 2024)
The Acclaim block plugin before 2019-06-26 for Moodle allows SQL Injection via delete_records.
0
Attacker Value
Unknown

CVE-2018-7316

Disclosure Date: February 22, 2018 (last updated November 26, 2024)
Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action.
0
Attacker Value
Unknown

CVE-2018-7317

Disclosure Date: February 22, 2018 (last updated November 26, 2024)
Backup Download exists in the Proclaim 9.1.1 component for Joomla! via a direct request for a .sql file under backup/.
0