Show filters
78 Total Results
Displaying 21-30 of 78
Sort by:
Attacker Value
Unknown

CVE-2019-12461

Disclosure Date: May 30, 2019 (last updated November 27, 2024)
Web Port 1.19.1 allows XSS via the /log type parameter.
0
Attacker Value
Unknown

CVE-2019-12460

Disclosure Date: May 30, 2019 (last updated November 27, 2024)
Web Port 1.19.1 allows XSS via the /access/setup type parameter.
0
Attacker Value
Unknown

CVE-2018-3639

Disclosure Date: May 22, 2018 (last updated November 26, 2024)
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.
Attacker Value
Unknown

CVE-2014-2592

Disclosure Date: March 09, 2018 (last updated November 26, 2024)
Unrestricted file upload vulnerability in Aruba Web Management portal allows remote attackers to execute arbitrary code by uploading a file with an executable extension.
0
Attacker Value
Unknown

CVE-2017-12613

Disclosure Date: October 24, 2017 (last updated November 08, 2023)
When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially revealing the contents of a different static heap value or resulting in program termination, and may represent an information disclosure or denial of service vulnerability to applications which call these APR functions with unvalidated external input.
Attacker Value
Unknown

CVE-2017-6869

Disclosure Date: August 08, 2017 (last updated November 26, 2024)
A vulnerability was discovered in Siemens ViewPort for Web Office Portal before revision number 1453 that could allow an unauthenticated remote user to upload arbitrary code and execute it with the permissions of the operating-system user running the web server by sending specially crafted network packets to port 443/TCP or port 80/TCP.
0
Attacker Value
Unknown

CVE-2016-8922

Disclosure Date: February 01, 2017 (last updated November 25, 2024)
Exphox WebRadar is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
0
Attacker Value
Unknown

CVE-2016-2901

Disclosure Date: June 26, 2016 (last updated November 25, 2024)
Cross-site request forgery (CSRF) vulnerability in the PA_Theme_Creator application in IBM WebSphere Portal 8.5 CF08 through CF10 and Web Content Manager allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
0
Attacker Value
Unknown

CVE-2014-2210

Disclosure Date: April 04, 2014 (last updated October 05, 2023)
Multiple directory traversal vulnerabilities in CA ERwin Web Portal 9.5 allow remote attackers to obtain sensitive information, bypass intended access restrictions, cause a denial of service, or possibly execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-1315

Disclosure Date: September 11, 2013 (last updated October 05, 2023)
Microsoft SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013; Office Web Apps 2010; Excel 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office for Mac 2011; Excel Viewer; and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
0