Show filters
83 Total Results
Displaying 21-30 of 83
Sort by:
Attacker Value
Unknown
CVE-2020-5396
Disclosure Date: July 30, 2020 (last updated February 21, 2025)
VMware GemFire versions prior to 9.10.0, 9.9.2, 9.8.7, and 9.7.6, and VMware Tanzu GemFire for VMs versions prior to 1.11.1 and 1.10.2, when deployed without a SecurityManager, contain a JMX service available which contains an insecure default configuration. This allows a malicious user to create an MLet mbean leading to remote code execution.
0
Attacker Value
Unknown
CVE-2019-11286
Disclosure Date: July 30, 2020 (last updated February 21, 2025)
VMware GemFire versions prior to 9.10.0, 9.9.1, 9.8.5, and 9.7.5, and VMware Tanzu GemFire for VMs versions prior to 1.11.0, 1.10.1, 1.9.2, and 1.8.2, contain a JMX service available to the network which does not properly restrict input. A remote authenticated malicious user may request against the service with a crafted set of credentials leading to remote code execution.
0
Attacker Value
Unknown
CVE-2019-3570
Disclosure Date: July 18, 2019 (last updated November 27, 2024)
Call to the scrypt_enc() function in HHVM can lead to heap corruption by using specifically crafted parameters (N, r and p). This happens if the parameters are configurable by an attacker for instance by providing the output of scrypt_enc() in a context where Hack/PHP code would attempt to verify it by re-running scrypt_enc() with the same parameters. This could result in information disclosure, memory being overwriten or crashes of the HHVM process. This issue affects versions 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.7.0, 4.8.0, versions 3.30.5 and below, and all versions in the 4.0, 4.1, and 4.2 series.
0
Attacker Value
Unknown
OS command injection vulnerability
Disclosure Date: May 15, 2019 (last updated November 27, 2024)
Dell EMC RecoverPoint versions prior to 5.1.3 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an OS command injection vulnerability in the installation feature of Boxmgmt CLI. A malicious boxmgmt user may potentially be able to execute arbitrary commands as root.
0
Attacker Value
Unknown
Dell EMC RecoverPoint Information Disclosure Vulnerability
Disclosure Date: November 13, 2018 (last updated November 27, 2024)
Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an information disclosure vulnerability. A malicious boxmgmt user may potentially be able to determine the existence of any system file via Boxmgmt CLI.
0
Attacker Value
Unknown
Dell EMC RecoverPoint Uncontrolled Resource Consumption Vulnerability
Disclosure Date: November 13, 2018 (last updated November 27, 2024)
Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an uncontrolled resource consumption vulnerability. A malicious boxmgmt user may potentially be able to consume large amount of CPU bandwidth to make the system slow or to determine the existence of any system file via Boxmgmt CLI.
0
Attacker Value
Unknown
CVE-2018-17293
Disclosure Date: September 21, 2018 (last updated November 27, 2024)
An issue was discovered in WAVM before 2018-09-16. The run function in Programs/wavm/wavm.cpp does not check whether there is Emscripten memory to store the command-line arguments passed by the input WebAssembly file's main function, which allows attackers to cause a denial of service (application crash by NULL pointer dereference) or possibly have unspecified other impact by crafting certain WebAssembly files.
0
Attacker Value
Unknown
CVE-2018-17292
Disclosure Date: September 21, 2018 (last updated November 27, 2024)
An issue was discovered in WAVM before 2018-09-16. The loadModule function in Include/Inline/CLI.h lacks checking of the file length before a file magic comparison, allowing attackers to cause a Denial of Service (application crash caused by out-of-bounds read) by crafting a file that has fewer than 4 bytes.
0
Attacker Value
Unknown
CVE-2018-16767
Disclosure Date: September 10, 2018 (last updated November 27, 2024)
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because of an unspecified "heap-buffer-overflow" condition in FunctionValidationContext::popAndValidateOperand.
0
Attacker Value
Unknown
CVE-2018-16765
Disclosure Date: September 10, 2018 (last updated November 27, 2024)
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because of an unspecified "heap-buffer-overflow" condition in FunctionValidationContext::else_.
0