Show filters
1,598 Total Results
Displaying 231-240 of 1,598
Sort by:
Attacker Value
Unknown

CVE-2019-11846

Disclosure Date: May 14, 2019 (last updated November 27, 2024)
/servlets/ajax_file_upload?fieldName=binary3 in dotCMS 5.1.1 allows XSS and HTML Injection.
0
Attacker Value
Unknown

CVE-2019-6440

Disclosure Date: January 16, 2019 (last updated November 27, 2024)
Zemana AntiMalware before 3.0.658 Beta mishandles update logic.
0
Attacker Value
Unknown

CVE-2017-7513

Disclosure Date: August 22, 2018 (last updated November 27, 2024)
It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fields. A man-in-the-middle attacker could use this flaw to spoof a PostgreSQL server using a specially crafted X.509 certificate.
0
Attacker Value
Unknown

McAfee ePolicy Orchestrator (ePO) - OS Command Injection vulnerability

Disclosure Date: June 13, 2018 (last updated November 08, 2023)
OS Command Injection vulnerability in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, 5.3.1, 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows attackers to run arbitrary OS commands with limited privileges via not sanitizing the user input data before exporting it into a CSV format output.
0
Attacker Value
Unknown

WebORB for Java by Midnight Coders, version 5.1.1.0, Action Message Format (AMF…

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
The Java implementations of AMF3 deserializers in WebORB for Java by Midnight Coders, version 5.1.1.0, derive class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExternalizable. A remote attacker with the ability to spoof or control an RMI server connection may be able to send serialized Java objects that execute arbitrary code when deserialized.
0
Attacker Value
Unknown

CVE-2017-3208

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
The Java implementation of AMF3 deserializers used by WebORB for Java by Midnight Coders, version 5.1.1.0, allows external entity references (XXEs) from XML documents embedded within AMF3 messages. If the XML parsing is handled incorrectly it could potentially expose sensitive data on the server, denial of service, or server side request forgery.
0
Attacker Value
Unknown

CVE-2016-8732

Disclosure Date: April 24, 2018 (last updated November 26, 2024)
Multiple security flaws exists in InvProtectDrv.sys which is a part of Invincea Dell Protected Workspace 5.1.1-22303. Weak restrictions on the driver communication channel and additional insufficient checks allow any application to turn off some of the protection mechanisms provided by the Invincea product.
Attacker Value
Unknown

CVE-2017-13262

Disclosure Date: April 04, 2018 (last updated November 26, 2024)
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing length decrement operation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-69271284.
0
Attacker Value
Unknown

CVE-2017-13261

Disclosure Date: April 04, 2018 (last updated November 26, 2024)
In bnep_process_control_packet of bnep_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-69177292.
0
Attacker Value
Unknown

CVE-2017-13256

Disclosure Date: April 04, 2018 (last updated November 26, 2024)
In process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68817966.
0