Show filters
37 Total Results
Displaying 21-30 of 37
Sort by:
Attacker Value
Unknown
CVE-2011-2474
Disclosure Date: June 09, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in the HTTP Server in Sybase EAServer 6.3.1 Developer Edition allows remote attackers to read arbitrary files via a /.\../\../\ sequence in a path.
0
Attacker Value
Unknown
CVE-2011-2475
Disclosure Date: June 09, 2011 (last updated October 04, 2023)
Format string vulnerability in ECTrace.dll in the iMailGateway service in the Internet Mail Gateway in OneBridge Server and DMZ Proxy in Sybase OneBridge Mobile Data Suite 5.5 and 5.6 allows remote attackers to execute arbitrary code via format string specifiers in unspecified string fields, related to authentication logging.
0
Attacker Value
Unknown
CVE-2011-0496
Disclosure Date: January 20, 2011 (last updated October 04, 2023)
Unspecified vulnerability in Sybase EAServer 5.x and 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), and WorkSpace, allows remote attackers to install arbitrary web services and execute arbitrary code, related to a "design vulnerability."
0
Attacker Value
Unknown
CVE-2011-0497
Disclosure Date: January 20, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in Sybase EAServer 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), and WorkSpace, allows remote attackers to read arbitrary files via "../\" (dot dot forward-slash backslash) sequences in a crafted request.
0
Attacker Value
Unknown
CVE-2008-0912
Disclosure Date: February 22, 2008 (last updated October 04, 2023)
Multiple heap-based buffer overflows in mlsrv10.exe in Sybase MobiLink 10.0.1.3629 and earlier, as used by SQL Anywhere Developer Edition 10.0.1.3415 and probably other products, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a long (1) username, (2) version, or (3) remote ID. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2006-3667
Disclosure Date: July 18, 2006 (last updated October 04, 2023)
Unspecified vulnerability in Sybase/Financial Fusion Consumer Banking Suite versions before 20060706 has unknown impact and remote attack vectors.
0
Attacker Value
Unknown
CVE-2006-2539
Disclosure Date: May 22, 2006 (last updated October 04, 2023)
Sybase EAServer 5.0 for HP-UX Itanium, 5.2 for IBM AIX, HP-UX PA-RISC, Linux x86, and Sun Solaris SPARC, and 5.3 for Sun Solaris SPARC does not properly protect passwords when they are being entered via the GUI, which allows local users to obtain the cleartext passwords via the getSelectedText function in javax.swing.JPasswordField component.
0
Attacker Value
Unknown
CVE-2006-1997
Disclosure Date: April 25, 2006 (last updated October 04, 2023)
Unspecified vulnerability in Sybase Pylon Anywhere groupware synchronization server before 7.0 allows local users to obtain sensitive information such as email and PIM data of another user via unknown attack vectors.
0
Attacker Value
Unknown
CVE-2006-1829
Disclosure Date: April 19, 2006 (last updated October 04, 2023)
EAServer Manager in Sybase EAServer 5.2 and 5.3 allows remote authenticated users, possibly guests, to obtain password credentials of arbitrary users via unspecified vectors involving (1) connection caches, (2) open password prompts, and (3) stored custom connection profiles.
0
Attacker Value
Unknown
CVE-2005-2297
Disclosure Date: July 19, 2005 (last updated February 22, 2025)
Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary code via a large javascript parameter.
0