Show filters
461 Total Results
Displaying 201-210 of 461
Sort by:
Attacker Value
Unknown
CVE-2019-18653
Disclosure Date: November 01, 2019 (last updated November 08, 2023)
A Cross Site Scripting (XSS) issue exists in Avast AntiVirus (Free, Internet Security, and Premiere Edition) 19.3.2369 build 19.3.4241.440 in the Network Notification Popup, allowing an attacker to execute JavaScript code via an SSID Name.
0
Attacker Value
Unknown
CVE-2019-17093
Disclosure Date: October 23, 2019 (last updated November 27, 2024)
An issue was discovered in Avast antivirus before 19.8 and AVG antivirus before 19.8. A DLL Preloading vulnerability allows an attacker to implant %WINDIR%\system32\wbemcomn.dll, which is loaded into a protected-light process (PPL) and might bypass some of the self-defense mechanisms. This affects all components that use WMI, e.g., AVGSvc.exe 19.6.4546.0 and TuneupSmartScan.dll 19.1.884.0.
0
Attacker Value
Unknown
CVE-2019-17434
Disclosure Date: October 10, 2019 (last updated November 27, 2024)
LavaLite through 5.7 has XSS via a crafted account name that is mishandled on the Manage Clients screen.
0
Attacker Value
Unknown
Avaya Aura Conferencing XSS
Disclosure Date: July 31, 2019 (last updated November 27, 2024)
A Cross-Site Scripting (XSS) vulnerability in the Web UI of Avaya Aura Conferencing may allow code execution and potentially disclose sensitive information. Affected versions of Avaya Aura Conferencing include all 8.x versions prior to 8.0 SP14 (8.0.14). Prior versions not listed were not evaluated.
0
Attacker Value
Unknown
CVE-2019-11230
Disclosure Date: July 18, 2019 (last updated November 27, 2024)
In Avast Antivirus before 19.4, a local administrator can trick the product into renaming arbitrary files by replacing the Logs\Update.log file with a symlink. The next time the product attempts to write to the log file, the target of the symlink is renamed. This defect can be exploited to rename a critical product file (e.g., AvastSvc.exe), causing the product to fail to start on the next system restart.
0
Attacker Value
Unknown
ACM SQL Injection
Disclosure Date: July 11, 2019 (last updated November 27, 2024)
A SQL injection vulnerability in the reporting component of Avaya Control Manager could allow an unauthenticated attacker to execute arbitrary SQL commands and retrieve sensitive data related to other users on the system. Affected versions of Avaya Control Manager include 7.x and 8.0.x versions prior to 8.0.4.0. Unsupported versions not listed here were not evaluated.
0
Attacker Value
Unknown
CVE-2019-17190
Disclosure Date: April 18, 2019 (last updated February 21, 2025)
A Local Privilege Escalation issue was discovered in Avast Secure Browser 76.0.1659.101. The vulnerability is due to an insecure ACL set by the AvastBrowserUpdate.exe (which is running as NT AUTHORITY\SYSTEM) when AvastSecureBrowser.exe checks for new updates. When the update check is triggered, the elevated process cleans the ACL of the Update.ini file in %PROGRAMDATA%\Avast Software\Browser\Update\ and sets all privileges to group Everyone. Because any low-privileged user can create, delete, or modify the Update.ini file stored in this location, an attacker with low privileges can create a hard link named Update.ini in this folder, and make it point to a file writable by NT AUTHORITY\SYSTEM. Once AvastBrowserUpdate.exe is triggered by the update check functionality, the DACL is set to a misconfigured value on the crafted Update.ini and, consequently, to the target file that was previously not writable by the low-privileged attacker.
0
Attacker Value
Unknown
Avaya IPOCC WebUI SQL Injection
Disclosure Date: April 04, 2019 (last updated November 27, 2024)
A SQL injection vulnerability in the WebUI component of IP Office Contact Center could allow an authenticated attacker to retrieve or alter sensitive data related to other users on the system. Affected versions of IP Office Contact Center include all 9.x and 10.x versions prior to 10.1.2.2.2-11201.1908. Unsupported versions not listed here were not evaluated.
0
Attacker Value
Unknown
CVE-2018-12572
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
Avast Free Antivirus prior to 19.1.2360 stores user credentials in memory upon login, which allows local users to obtain sensitive information by dumping AvastUI.exe application memory and parsing the data.
0
Attacker Value
Unknown
Avaya one-X Communicator Weak Encryption
Disclosure Date: February 27, 2019 (last updated November 27, 2024)
Avaya one-X Communicator uses weak cryptographic algorithms in the client authentication component that could allow a local attacker to decrypt sensitive information. Affected versions include all 6.2.x versions prior to 6.2 SP13.
0