Show filters
97 Total Results
Displaying 21-30 of 97
Sort by:
Attacker Value
Unknown
CVE-2020-1968
Disclosure Date: September 09, 2020 (last updated February 22, 2025)
The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the attacker being able to eavesdrop on all encrypted communications sent over that TLS connection. The attack can only be exploited if an implementation re-uses a DH secret across multiple TLS connections. Note that this issue only impacts DH ciphersuites and not ECDH ciphersuites. This issue affects OpenSSL 1.0.2 which is out of support and no longer receiving public updates. OpenSSL 1.1.1 is not vulnerable to this issue. Fixed in OpenSSL 1.0.2w (Affected 1.0.2-1.0.2v).
0
Attacker Value
Unknown
CVE-2020-8813
Disclosure Date: February 22, 2020 (last updated February 21, 2025)
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege.
0
Attacker Value
Unknown
CVE-2019-20330
Disclosure Date: January 03, 2020 (last updated February 21, 2025)
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
0
Attacker Value
Unknown
CVE-2019-14907
Disclosure Date: December 10, 2019 (last updated February 21, 2025)
All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during the NTLMSSP authentication exchange. In the Samba AD DC in particular, this may cause a long-lived process(such as the RPC server) to terminate. (In the file server case, the most likely target, smbd, operates as process-per-client and so a crash there is harmless).
0
Attacker Value
Unknown
CVE-2012-1105
Disclosure Date: December 05, 2019 (last updated November 27, 2024)
An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. The Central Authentication Service client library archives the debug logging file in an insecure manner.
0
Attacker Value
Unknown
CVE-2012-1104
Disclosure Date: December 05, 2019 (last updated November 27, 2024)
A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the way proxying of services are managed.
0
Attacker Value
Unknown
CVE-2012-4428
Disclosure Date: December 02, 2019 (last updated November 27, 2024)
openslp: SLPIntersectStringList()' Function has a DoS vulnerability
0
Attacker Value
Unknown
CVE-2011-4968
Disclosure Date: November 19, 2019 (last updated November 27, 2024)
nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)
0
Attacker Value
Unknown
CVE-2011-1588
Disclosure Date: November 14, 2019 (last updated November 27, 2024)
Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error.
0
Attacker Value
Unknown
CVE-2013-1934
Disclosure Date: October 31, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.0rc1 before 1.2.14 allows remote authenticated users to inject arbitrary web script or HTML via a complex value.
0