Show filters
256 Total Results
Displaying 231-240 of 256
Sort by:
Attacker Value
Unknown

CVE-2017-5912

Disclosure Date: May 05, 2017 (last updated November 08, 2023)
The FOREX.com FOREXTrader for iPhone app 2.9.12 through 2.9.14 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2017-5645

Disclosure Date: April 17, 2017 (last updated November 08, 2023)
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
Attacker Value
Unknown

CVE-2016-10320

Disclosure Date: April 06, 2017 (last updated November 26, 2024)
textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if a web application accepts names of arbitrary uploaded files.
0
Attacker Value
Unknown

CVE-2017-7183

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
The TFTP server in ExtraPuTTY 0.30 and earlier allows remote attackers to cause a denial of service (crash) via a large (1) read or (2) write TFTP protocol message.
0
Attacker Value
Unknown

CVE-2016-3101

Disclosure Date: February 09, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the Extra Columns plugin before 1.17 in Jenkins allows remote attackers to inject arbitrary web script or HTML by leveraging failure to filter tool tips through the configured markup formatter.
Attacker Value
Unknown

CVE-2015-2092

Disclosure Date: March 09, 2015 (last updated October 05, 2023)
The AnnotationX.AnnList.1 ActiveX control in Agilent Technologies Feature Extraction allows remote attackers to execute arbitrary code via a crafted object parameter in the Insert function, related to "Index Out-Of-Bounds."
0
Attacker Value
Unknown

CVE-2014-8600

Disclosure Date: December 08, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in KDE-Runtime 4.14.3 and earlier, kwebkitpart 1.3.4 and earlier, and kio-extras 5.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via a crafted URI using the (1) zip, (2) trash, (3) tar, (4) thumbnail, (5) smtps, (6) smtp, (7) smb, (8) remote, (9) recentdocuments, (10) nntps, (11) nntp, (12) network, (13) mbox, (14) ldaps, (15) ldap, (16) fonts, (17) file, (18) desktop, (19) cgi, (20) bookmarks, or (21) ar scheme, which is not properly handled in an error message.
0
Attacker Value
Unknown

CVE-2012-5542

Disclosure Date: December 03, 2012 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the Commerce Extra Panes module 7.x-1.x before 7.x-1.1 in Drupal allows remote attackers to hijack the authentication of administrators for requests that enable or disable a Commerce extra panes pane via unspecified vectors related to "the link to reorder items."
0
Attacker Value
Unknown

CVE-2012-2120

Disclosure Date: May 18, 2012 (last updated October 04, 2023)
latex2man in texlive-extra-utils 2011.20120322, and possibly other versions or packages, when used with the H or T option, allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
0
Attacker Value
Unknown

CVE-2011-4222

Disclosure Date: November 01, 2011 (last updated October 04, 2023)
Unspecified vulnerability in Investintech.com Able2Extract and Able2Extract Server allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document.
0