Show filters
284 Total Results
Displaying 201-210 of 284
Sort by:
Attacker Value
Unknown
CVE-2015-8934
Disclosure Date: September 20, 2016 (last updated November 25, 2024)
The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted rar file.
0
Attacker Value
Unknown
CVE-2016-5847
Disclosure Date: August 13, 2016 (last updated November 25, 2024)
SAP SAPCAR allows local users to change the permissions of arbitrary files and consequently gain privileges via a hard link attack on files extracted from an archive, possibly related to SAP Security Note 2327384.
0
Attacker Value
Unknown
CVE-2016-6232
Disclosure Date: August 02, 2016 (last updated November 25, 2024)
Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads.
0
Attacker Value
Unknown
CVE-2016-1541
Disclosure Date: May 07, 2016 (last updated November 25, 2024)
Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to execute arbitrary code via crafted entry-size values in a ZIP archive.
0
Attacker Value
Unknown
CVE-2015-7521
Disclosure Date: January 29, 2016 (last updated November 25, 2024)
The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, allows attackers to bypass intended parent table access restrictions via unspecified partition-level operations.
0
Attacker Value
Unknown
CVE-2015-1772
Disclosure Date: December 21, 2015 (last updated November 08, 2023)
The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, mishandles simple unauthenticated and anonymous bind configurations, which allows remote attackers to bypass authentication via a crafted LDAP request.
0
Attacker Value
Unknown
CVE-2014-9736
Disclosure Date: August 04, 2015 (last updated October 05, 2023)
GE Healthcare Centricity Clinical Archive Audit Trail Repository has a default password of initinit for the (1) SSL key manager and (2) server keystore; (3) keystore_password for the server truststore; and atna for the (4) primary storage database and (5) archive storage database, which has unspecified impact and attack vectors.
0
Attacker Value
Unknown
CVE-2015-0556
Disclosure Date: April 08, 2015 (last updated October 05, 2023)
Open-source ARJ archiver 3.10.22 allows remote attackers to conduct directory traversal attacks via a symlink attack in an ARJ archive.
0
Attacker Value
Unknown
CVE-2015-0557
Disclosure Date: April 08, 2015 (last updated October 05, 2023)
Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in a path in an ARJ archive.
0
Attacker Value
Unknown
CVE-2015-2782
Disclosure Date: April 08, 2015 (last updated October 05, 2023)
Buffer overflow in Open-source ARJ archiver 3.10.22 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ARJ archive.
0