Show filters
548 Total Results
Displaying 251-260 of 548
Sort by:
Attacker Value
Unknown
CVE-2012-1114
Disclosure Date: December 05, 2019 (last updated November 27, 2024)
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_id action. and the filteruid parameter to list.php.
0
Attacker Value
Unknown
CVE-2012-1115
Disclosure Date: December 05, 2019 (last updated November 27, 2024)
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php.
0
Attacker Value
Unknown
CVE-2012-1105
Disclosure Date: December 05, 2019 (last updated November 27, 2024)
An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. The Central Authentication Service client library archives the debug logging file in an insecure manner.
0
Attacker Value
Unknown
CVE-2013-4235
Disclosure Date: December 03, 2019 (last updated November 27, 2024)
shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
0
Attacker Value
Unknown
CVE-2019-14901
Disclosure Date: November 29, 2019 (last updated November 27, 2024)
A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability allows a remote attacker to cause a system crash, resulting in a denial of service, or execute arbitrary code. The highest threat with this vulnerability is with the availability of the system. If code execution occurs, the code will run with the permissions of root. This will affect both confidentiality and integrity of files on the system.
0
Attacker Value
Unknown
CVE-2019-14895
Disclosure Date: November 29, 2019 (last updated November 27, 2024)
A heap-based buffer overflow was discovered in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw could occur when the station attempts a connection negotiation during the handling of the remote devices country settings. This could allow the remote device to cause a denial of service (system crash) or possibly execute arbitrary code.
0
Attacker Value
Unknown
CVE-2019-18660
Disclosure Date: November 27, 2019 (last updated November 08, 2023)
The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs, aka CID-39e72bf96f58. This is related to arch/powerpc/kernel/entry_64.S and arch/powerpc/kernel/security.c.
0
Attacker Value
Unknown
CVE-2019-14896
Disclosure Date: November 27, 2019 (last updated November 27, 2024)
A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker could cause a denial of service (system crash) or, possibly execute arbitrary code, when the lbs_ibss_join_existing function is called after a STA connects to an AP.
0
Attacker Value
Unknown
CVE-2019-18678
Disclosure Date: November 26, 2019 (last updated November 08, 2023)
An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend software to a Squid instance that splits the HTTP Request pipeline differently. The resulting Response messages corrupt caches (between a client and Squid) with attacker-controlled content at arbitrary URLs. Effects are isolated to software between the attacker client and Squid. There are no effects on Squid itself, nor on any upstream servers. The issue is related to a request header containing whitespace between a header name and a colon.
0
Attacker Value
Unknown
CVE-2019-18679
Disclosure Date: November 26, 2019 (last updated November 08, 2023)
An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits within heap memory allocation. This information reduces ASLR protections and may aid attackers isolating memory areas to target for remote code execution attacks.
0