Show filters
284 Total Results
Displaying 221-230 of 284
Sort by:
Attacker Value
Unknown
CVE-2012-1827
Disclosure Date: June 13, 2012 (last updated October 04, 2023)
The web service in AutoFORM PDM Archive before 7.1 does not have authorization requirements, which allows remote authenticated users to perform database operations via a SOAP request, as demonstrated by the initializeQueryDatabase2 request.
0
Attacker Value
Unknown
CVE-2012-3347
Disclosure Date: June 13, 2012 (last updated October 04, 2023)
AutoFORM PDM Archive before 7.0 implements user accounts in a way that allows for JMX Console authentication, which allows remote authenticated users to bypass intended access restrictions via the /jmx-console URI, and then upload and execute arbitrary JSP code via a JBoss remote-deployment mechanism, a different vulnerability than CVE-2012-1828.
0
Attacker Value
Unknown
CVE-2012-1829
Disclosure Date: June 13, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in AutoFORM PDM Archive before 6.920 allow remote authenticated users to inject arbitrary web script or HTML via unspecified fields.
0
Attacker Value
Unknown
CVE-2012-1828
Disclosure Date: June 13, 2012 (last updated October 04, 2023)
The administrative functions in AutoFORM PDM Archive before 7.1 do not have authorization requirements, which allows remote authenticated users to perform administrative actions by leveraging knowledge of a hidden function, as demonstrated by the password-change function.
0
Attacker Value
Unknown
CVE-2011-1779
Disclosure Date: April 13, 2012 (last updated October 04, 2023)
Multiple use-after-free vulnerabilities in libarchive 2.8.4 and 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted (1) TAR archive or (2) ISO9660 image.
0
Attacker Value
Unknown
CVE-2010-4666
Disclosure Date: April 13, 2012 (last updated October 04, 2023)
Buffer overflow in libarchive 3.0 pre-release code allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CAB file, which is not properly handled during the reading of Huffman code data within LZX compressed data.
0
Attacker Value
Unknown
CVE-2011-1777
Disclosure Date: April 13, 2012 (last updated October 04, 2023)
Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functions in archive_read_support_format_iso9660.c in libarchive through 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ISO9660 image.
0
Attacker Value
Unknown
CVE-2011-1778
Disclosure Date: April 13, 2012 (last updated October 04, 2023)
Buffer overflow in libarchive through 2.8.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TAR archive.
0
Attacker Value
Unknown
CVE-2012-0900
Disclosure Date: January 20, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Beehive Forum 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) forum/register.php or (2) forum/logon.php.
0
Attacker Value
Unknown
CVE-2010-4417
Disclosure Date: January 19, 2011 (last updated October 04, 2023)
Unspecified vulnerability in the Services for Beehive component in Oracle Fusion Middleware 2.0.1.0, 2.0.1.1, 2.0.1.2, 2.0.1.2.1, and 2.0.1.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable third party coordinator that voice-servlet/prompt-qa/Index.jspf does not properly handle null (%00) bytes in the evaluation parameter that is used in a filename, which allows attackers to create a file with an executable extension and execute arbitrary JSP code.
0