Show filters
284 Total Results
Displaying 221-230 of 284
Sort by:
Attacker Value
Unknown

CVE-2012-1827

Disclosure Date: June 13, 2012 (last updated October 04, 2023)
The web service in AutoFORM PDM Archive before 7.1 does not have authorization requirements, which allows remote authenticated users to perform database operations via a SOAP request, as demonstrated by the initializeQueryDatabase2 request.
0
Attacker Value
Unknown

CVE-2012-3347

Disclosure Date: June 13, 2012 (last updated October 04, 2023)
AutoFORM PDM Archive before 7.0 implements user accounts in a way that allows for JMX Console authentication, which allows remote authenticated users to bypass intended access restrictions via the /jmx-console URI, and then upload and execute arbitrary JSP code via a JBoss remote-deployment mechanism, a different vulnerability than CVE-2012-1828.
0
Attacker Value
Unknown

CVE-2012-1829

Disclosure Date: June 13, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in AutoFORM PDM Archive before 6.920 allow remote authenticated users to inject arbitrary web script or HTML via unspecified fields.
0
Attacker Value
Unknown

CVE-2012-1828

Disclosure Date: June 13, 2012 (last updated October 04, 2023)
The administrative functions in AutoFORM PDM Archive before 7.1 do not have authorization requirements, which allows remote authenticated users to perform administrative actions by leveraging knowledge of a hidden function, as demonstrated by the password-change function.
0
Attacker Value
Unknown

CVE-2011-1779

Disclosure Date: April 13, 2012 (last updated October 04, 2023)
Multiple use-after-free vulnerabilities in libarchive 2.8.4 and 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted (1) TAR archive or (2) ISO9660 image.
0
Attacker Value
Unknown

CVE-2010-4666

Disclosure Date: April 13, 2012 (last updated October 04, 2023)
Buffer overflow in libarchive 3.0 pre-release code allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CAB file, which is not properly handled during the reading of Huffman code data within LZX compressed data.
0
Attacker Value
Unknown

CVE-2011-1777

Disclosure Date: April 13, 2012 (last updated October 04, 2023)
Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functions in archive_read_support_format_iso9660.c in libarchive through 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ISO9660 image.
0
Attacker Value
Unknown

CVE-2011-1778

Disclosure Date: April 13, 2012 (last updated October 04, 2023)
Buffer overflow in libarchive through 2.8.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TAR archive.
0
Attacker Value
Unknown

CVE-2012-0900

Disclosure Date: January 20, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Beehive Forum 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) forum/register.php or (2) forum/logon.php.
0
Attacker Value
Unknown

CVE-2010-4417

Disclosure Date: January 19, 2011 (last updated October 04, 2023)
Unspecified vulnerability in the Services for Beehive component in Oracle Fusion Middleware 2.0.1.0, 2.0.1.1, 2.0.1.2, 2.0.1.2.1, and 2.0.1.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable third party coordinator that voice-servlet/prompt-qa/Index.jspf does not properly handle null (%00) bytes in the evaluation parameter that is used in a filename, which allows attackers to create a file with an executable extension and execute arbitrary JSP code.
0