Show filters
461 Total Results
Displaying 241-250 of 461
Sort by:
Attacker Value
Unknown
CVE-2016-2192
Disclosure Date: June 06, 2017 (last updated November 26, 2024)
PostgreSQL PL/Java before 1.5.0 allows remote authenticated users to alter type mappings for types they do not own.
0
Attacker Value
Unknown
CVE-2016-0767
Disclosure Date: June 06, 2017 (last updated November 26, 2024)
PostgreSQL PL/Java before 1.5.0 allows remote authenticated users with USAGE permission on the public schema to alter the public schema classpath.
0
Attacker Value
Unknown
CVE-2017-9212
Disclosure Date: May 23, 2017 (last updated November 26, 2024)
The Bluetooth stack on the BMW 330i 2011 allows a remote crash of the CD/Multimedia software via %x or %c format string specifiers in a device name.
0
Attacker Value
Unknown
CVE-2017-8938
Disclosure Date: May 15, 2017 (last updated November 08, 2023)
The Radio Javan app 9.3.4 through 9.6.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2017-6519
Disclosure Date: May 01, 2017 (last updated November 08, 2023)
avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link, which allows remote attackers to cause a denial of service (traffic amplification) and may cause information leakage by obtaining potentially sensitive information from the responding device via port-5353 UDP packets. NOTE: this may overlap CVE-2015-2809.
0
Attacker Value
Unknown
CVE-2017-8307
Disclosure Date: April 27, 2017 (last updated November 26, 2024)
In Avast Antivirus before v17, using the LPC interface API exposed by the AvastSVC.exe Windows service, it is possible to launch predefined binaries, or replace or delete arbitrary files. This vulnerability is exploitable by any unprivileged user when Avast Self-Defense is disabled. It is also exploitable in conjunction with CVE-2017-8308 when Avast Self-Defense is enabled. The vulnerability allows for Denial of Service attacks and hiding traces of a possible attack.
0
Attacker Value
Unknown
CVE-2017-8308
Disclosure Date: April 27, 2017 (last updated November 26, 2024)
In Avast Antivirus before v17, an unprivileged user (and thus malware or a virus) can mark an arbitrary process as Trusted from the perspective of the Avast product. This bypasses the Self-Defense feature of the product, opening a door to subsequent attack on many of its components.
0
Attacker Value
Unknown
CVE-2017-5567
Disclosure Date: March 21, 2017 (last updated November 26, 2024)
Code injection vulnerability in Avast Premier 12.3 (and earlier), Internet Security 12.3 (and earlier), Pro Antivirus 12.3 (and earlier), and Free Antivirus 12.3 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any Avast process via a "DoubleAgent" attack. One perspective on this issue is that (1) these products do not use the Protected Processes feature, and therefore an attacker can enter an arbitrary Application Verifier Provider DLL under Image File Execution Options in the registry; (2) the self-protection mechanism is intended to block all local processes (regardless of privileges) from modifying Image File Execution Options for these products; and (3) this mechanism can be bypassed by an attacker who temporarily renames Image File Execution Options during the attack.
0
Attacker Value
Unknown
CVE-2017-5145
Disclosure Date: February 13, 2017 (last updated November 26, 2024)
An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. Successful exploitation of this CROSS-SITE REQUEST FORGERY (CSRF) vulnerability can allow execution of unauthorized actions on the device such as configuration parameter changes, and saving modified configuration.
0
Attacker Value
Unknown
CVE-2017-5144
Disclosure Date: February 13, 2017 (last updated November 26, 2024)
An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. The access control flaw allows access to most application functions without authentication.
0