Show filters
87 Total Results
Displaying 21-30 of 87
Sort by:
Attacker Value
Unknown

CVE-2020-24916

Disclosure Date: September 09, 2020 (last updated November 28, 2024)
CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.
Attacker Value
Unknown

CVE-2020-16094

Disclosure Date: July 28, 2020 (last updated November 08, 2023)
In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recursion into subdirectories during a rebuild of the folder tree.
Attacker Value
Unknown

CVE-2020-15917

Disclosure Date: July 23, 2020 (last updated November 08, 2023)
common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.
Attacker Value
Unknown

CVE-2020-12872

Disclosure Date: May 15, 2020 (last updated November 08, 2023)
yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks, if running on an Erlang/OTP virtual machine with a version less than 21.0.
Attacker Value
Unknown

CVE-2013-2474

Disclosure Date: January 27, 2020 (last updated November 28, 2024)
Directory traversal vulnerability in AWS XMS 2.5 allows remote attackers to view arbitrary files via the 'what' parameter.
Attacker Value
Unknown

CVE-2016-1000108

Disclosure Date: December 10, 2019 (last updated November 27, 2024)
yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.
Attacker Value
Unknown

CVE-2011-4350

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user could use this flaw to obtain content of arbitrary local files via specially-crafted URL request.
Attacker Value
Unknown

CVE-2012-5527

Disclosure Date: November 25, 2019 (last updated November 27, 2024)
Claws Mail vCalendar plugin: credentials exposed on interface
Attacker Value
Unknown

CVE-2019-12896

Disclosure Date: June 19, 2019 (last updated November 27, 2024)
Edraw Max 7.9.3 has Heap Corruption starting at ntdll!RtlpNtMakeTemporaryKey+0x0000000000001a77.
0
Attacker Value
Unknown

CVE-2019-12897

Disclosure Date: June 19, 2019 (last updated November 27, 2024)
Edraw Max 7.9.3 has a Read Access Violation at the Instruction Pointer after a call from ObjectModule!Paint::Clear+0x0000000000000074.
0