Show filters
284 Total Results
Displaying 201-210 of 284
Sort by:
Attacker Value
Unknown

CVE-2015-8934

Disclosure Date: September 20, 2016 (last updated November 25, 2024)
The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted rar file.
0
Attacker Value
Unknown

CVE-2016-5847

Disclosure Date: August 13, 2016 (last updated November 25, 2024)
SAP SAPCAR allows local users to change the permissions of arbitrary files and consequently gain privileges via a hard link attack on files extracted from an archive, possibly related to SAP Security Note 2327384.
0
Attacker Value
Unknown

CVE-2016-6232

Disclosure Date: August 02, 2016 (last updated November 25, 2024)
Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads.
0
Attacker Value
Unknown

CVE-2016-1541

Disclosure Date: May 07, 2016 (last updated November 25, 2024)
Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to execute arbitrary code via crafted entry-size values in a ZIP archive.
0
Attacker Value
Unknown

CVE-2015-7521

Disclosure Date: January 29, 2016 (last updated November 25, 2024)
The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, allows attackers to bypass intended parent table access restrictions via unspecified partition-level operations.
0
Attacker Value
Unknown

CVE-2015-1772

Disclosure Date: December 21, 2015 (last updated November 08, 2023)
The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, mishandles simple unauthenticated and anonymous bind configurations, which allows remote attackers to bypass authentication via a crafted LDAP request.
0
Attacker Value
Unknown

CVE-2014-9736

Disclosure Date: August 04, 2015 (last updated October 05, 2023)
GE Healthcare Centricity Clinical Archive Audit Trail Repository has a default password of initinit for the (1) SSL key manager and (2) server keystore; (3) keystore_password for the server truststore; and atna for the (4) primary storage database and (5) archive storage database, which has unspecified impact and attack vectors.
0
Attacker Value
Unknown

CVE-2015-0556

Disclosure Date: April 08, 2015 (last updated October 05, 2023)
Open-source ARJ archiver 3.10.22 allows remote attackers to conduct directory traversal attacks via a symlink attack in an ARJ archive.
0
Attacker Value
Unknown

CVE-2015-0557

Disclosure Date: April 08, 2015 (last updated October 05, 2023)
Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in a path in an ARJ archive.
0
Attacker Value
Unknown

CVE-2015-2782

Disclosure Date: April 08, 2015 (last updated October 05, 2023)
Buffer overflow in Open-source ARJ archiver 3.10.22 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ARJ archive.
0