Show filters
31 Total Results
Displaying 21-30 of 31
Sort by:
Attacker Value
Unknown
CVE-2018-16866
Disclosure Date: January 11, 2019 (last updated November 27, 2024)
An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable.
0
Attacker Value
Unknown
CVE-2018-7799
Disclosure Date: November 02, 2018 (last updated November 27, 2024)
A DLL hijacking vulnerability exists in Schneider Electric Software Update (SESU), all versions prior to V2.2.0, which could allow an attacker to execute arbitrary code on the targeted system when placing a specific DLL file.
0
Attacker Value
Unknown
CVE-2017-6466
Disclosure Date: March 11, 2017 (last updated November 26, 2024)
F-Secure Software Updater 2.20, as distributed in several F-Secure products, downloads installation packages over plain http and does not perform file integrity validation after download. Man-in-the-middle attackers can replace the file with their own executable which will be executed under the SYSTEM account. Note that when Software Updater is configured to install updates automatically, it checks if the downloaded file is digitally signed by default, but does not check the author of the signature. When running in manual mode (default), no signature check is performed.
0
Attacker Value
Unknown
CVE-2016-1731
Disclosure Date: March 14, 2016 (last updated November 25, 2024)
Apple Software Update before 2.2 on Windows does not use HTTPS, which makes it easier for man-in-the-middle attackers to spoof updates by modifying the client-server data stream.
0
Attacker Value
Unknown
CVE-2015-5442
Disclosure Date: September 29, 2015 (last updated October 05, 2023)
Unspecified vulnerability in HP Software Update before 5.005.002.002 allows local users to gain privileges via unknown vectors.
0
Attacker Value
Unknown
CVE-2013-0655
Disclosure Date: January 21, 2013 (last updated October 05, 2023)
The client in Schneider Electric Software Update (SESU) Utility 1.0.x and 1.1.x does not ensure that updates have a valid origin, which allows man-in-the-middle attackers to spoof updates, and consequently execute arbitrary code, by modifying the data stream on TCP port 80.
0
Attacker Value
Unknown
CVE-2008-2390
Disclosure Date: May 21, 2008 (last updated October 04, 2023)
Hpufunction.dll 4.0.0.1 in HP Software Update exposes the unsafe (1) ExecuteAsync and (2) Execute methods, which allows remote attackers to execute arbitrary code via an absolute pathname in the first argument.
0
Attacker Value
Unknown
CVE-2008-0712
Disclosure Date: April 25, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the HP HPeDiag (aka eSupportDiagnostics) ActiveX control in hpediag.dll in HP Software Update 4.000.009.002 and earlier allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors. NOTE: this might overlap CVE-2007-6513.
0
Attacker Value
Unknown
CVE-2007-6506
Disclosure Date: December 20, 2007 (last updated October 04, 2023)
The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and earlier, including 3.0.8.4, allows remote attackers to (1) overwrite and corrupt arbitrary files via arguments to the SaveToFile method, and possibly (2) access arbitrary files via the LoadDataFromFile method.
0
Attacker Value
Unknown
CVE-2007-0463
Disclosure Date: January 29, 2007 (last updated October 04, 2023)
Format string vulnerability in Apple Software Update 2.0.5 on Mac OS X 10.4.8 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in (1) SWUTMP or (2) SUCATALOG filenames, or using the (3) application/x-apple.sucatalog+xml MIME type.
0