Show filters
1,081 Total Results
Displaying 251-260 of 1,081
Sort by:
Attacker Value
Unknown

Path traversal in the backup & restore functionality of ProSyst mBS SDK and Bos…

Disclosure Date: August 21, 2019 (last updated November 27, 2024)
A directory traversal vulnerability in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.2.0 allows remote attackers to write or delete files at any location.
Attacker Value
Unknown

Path traversal in ProSyst mBS SDK and Bosch IoT Gateway Software

Disclosure Date: August 21, 2019 (last updated November 27, 2024)
A HTTP Traversal Attack in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.0.2 allows remote attackers to read files outside the http root.
0
Attacker Value
Unknown

Leakage of stack traces in the backup & restore functionality of ProSyst mBS SD…

Disclosure Date: August 21, 2019 (last updated November 27, 2024)
Leakage of stack traces in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.2.0 allows remote attackers to gather information about the file system structure.
0
Attacker Value
Unknown

Server-side request forgery in the backup & restore functionality of ProSyst mB…

Disclosure Date: August 21, 2019 (last updated November 27, 2024)
A Server-Side Request Forgery (SSRF) vulnerability in the backup & restore functionality in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.3.0 allows a remote attacker to forge GET requests to arbitrary URLs. In addition, this could potentially allow an attacker to read sensitive zip files from the local server.
0
Attacker Value
Unknown

CVE-2019-11148

Disclosure Date: August 19, 2019 (last updated November 27, 2024)
Improper permissions in the installer for Intel(R) Remote Displays SDK before version 2.0.1 R2 may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown

CVE-2017-6217

Disclosure Date: July 10, 2019 (last updated November 27, 2024)
paypal/adaptivepayments-sdk-php v3.9.2 is vulnerable to a reflected XSS in the SetPaymentOptions.php resulting code execution
0
Attacker Value
Unknown

CVE-2017-6216

Disclosure Date: July 03, 2019 (last updated November 27, 2024)
novaksolutions/infusionsoft-php-sdk v2016-10-31 is vulnerable to a reflected XSS in the leadscoring.php resulting code execution
0
Attacker Value
Unknown

CVE-2018-19450

Disclosure Date: June 17, 2019 (last updated November 27, 2024)
A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 5.4.0.1031 when parsing a launch action. An attacker can leverage this to gain remote code execution.
0
Attacker Value
Unknown

CVE-2018-19446

Disclosure Date: June 17, 2019 (last updated November 27, 2024)
A File Write can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the JavaScript API Doc.createDataObject is used. An attacker can leverage this to gain remote code execution.
0
Attacker Value
Unknown

CVE-2018-19448

Disclosure Date: June 17, 2019 (last updated November 27, 2024)
In Foxit Reader SDK (ActiveX) Professional 5.4.0.1031, an uninitialized object in IReader_ContentProvider::GetDocEventHandler occurs when embedding the control into Office documents. By opening a specially crafted document, an attacker can trigger an out of bounds write condition, possibly leveraging this to gain remote code execution.
0