Show filters
37 Total Results
Displaying 21-30 of 37
Sort by:
Attacker Value
Unknown

CVE-2011-2474

Disclosure Date: June 09, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in the HTTP Server in Sybase EAServer 6.3.1 Developer Edition allows remote attackers to read arbitrary files via a /.\../\../\ sequence in a path.
0
Attacker Value
Unknown

CVE-2011-2475

Disclosure Date: June 09, 2011 (last updated October 04, 2023)
Format string vulnerability in ECTrace.dll in the iMailGateway service in the Internet Mail Gateway in OneBridge Server and DMZ Proxy in Sybase OneBridge Mobile Data Suite 5.5 and 5.6 allows remote attackers to execute arbitrary code via format string specifiers in unspecified string fields, related to authentication logging.
0
Attacker Value
Unknown

CVE-2011-0496

Disclosure Date: January 20, 2011 (last updated October 04, 2023)
Unspecified vulnerability in Sybase EAServer 5.x and 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), and WorkSpace, allows remote attackers to install arbitrary web services and execute arbitrary code, related to a "design vulnerability."
0
Attacker Value
Unknown

CVE-2011-0497

Disclosure Date: January 20, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in Sybase EAServer 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), and WorkSpace, allows remote attackers to read arbitrary files via "../\" (dot dot forward-slash backslash) sequences in a crafted request.
0
Attacker Value
Unknown

CVE-2008-0912

Disclosure Date: February 22, 2008 (last updated October 04, 2023)
Multiple heap-based buffer overflows in mlsrv10.exe in Sybase MobiLink 10.0.1.3629 and earlier, as used by SQL Anywhere Developer Edition 10.0.1.3415 and probably other products, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a long (1) username, (2) version, or (3) remote ID. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2006-3667

Disclosure Date: July 18, 2006 (last updated October 04, 2023)
Unspecified vulnerability in Sybase/Financial Fusion Consumer Banking Suite versions before 20060706 has unknown impact and remote attack vectors.
0
Attacker Value
Unknown

CVE-2006-2539

Disclosure Date: May 22, 2006 (last updated October 04, 2023)
Sybase EAServer 5.0 for HP-UX Itanium, 5.2 for IBM AIX, HP-UX PA-RISC, Linux x86, and Sun Solaris SPARC, and 5.3 for Sun Solaris SPARC does not properly protect passwords when they are being entered via the GUI, which allows local users to obtain the cleartext passwords via the getSelectedText function in javax.swing.JPasswordField component.
0
Attacker Value
Unknown

CVE-2006-1997

Disclosure Date: April 25, 2006 (last updated October 04, 2023)
Unspecified vulnerability in Sybase Pylon Anywhere groupware synchronization server before 7.0 allows local users to obtain sensitive information such as email and PIM data of another user via unknown attack vectors.
0
Attacker Value
Unknown

CVE-2006-1829

Disclosure Date: April 19, 2006 (last updated October 04, 2023)
EAServer Manager in Sybase EAServer 5.2 and 5.3 allows remote authenticated users, possibly guests, to obtain password credentials of arbitrary users via unspecified vectors involving (1) connection caches, (2) open password prompts, and (3) stored custom connection profiles.
0
Attacker Value
Unknown

CVE-2005-2297

Disclosure Date: July 19, 2005 (last updated February 22, 2025)
Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary code via a large javascript parameter.
0