Show filters
734 Total Results
Displaying 251-260 of 734
Sort by:
Attacker Value
Unknown
CVE-2018-5341
Disclosure Date: April 18, 2018 (last updated November 26, 2024)
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploading and modifying scripts.
0
Attacker Value
Unknown
CVE-2018-5338
Disclosure Date: April 18, 2018 (last updated November 26, 2024)
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechanism.
0
Attacker Value
Unknown
CVE-2018-8976
Disclosure Date: March 25, 2018 (last updated November 26, 2024)
In Exiv2 0.26, jpgimage.cpp allows remote attackers to cause a denial of service (image.cpp Exiv2::Internal::stringFormat out-of-bounds read) via a crafted file.
0
Attacker Value
Unknown
CVE-2014-8130
Disclosure Date: March 12, 2018 (last updated November 26, 2024)
The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c, as demonstrated by tiffdither.
0
Attacker Value
Unknown
CVE-2017-16924
Disclosure Date: February 19, 2018 (last updated November 26, 2024)
Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<client_id>/collections/##/usermgmt.xml URL, as demonstrated by passwords and Wi-Fi keys. This is fixed in build 100157.
0
Attacker Value
Unknown
CVE-2016-8610
Disclosure Date: November 13, 2017 (last updated January 27, 2024)
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.
0
Attacker Value
Unknown
CVE-2017-5113
Disclosure Date: October 27, 2017 (last updated November 08, 2023)
Math overflow in Skia in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2017-5116
Disclosure Date: October 27, 2017 (last updated November 08, 2023)
Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2017-5114
Disclosure Date: October 27, 2017 (last updated November 08, 2023)
Inappropriate use of partition alloc in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Windows, and Mac, and 61.0.3163.81 for Android, allowed a remote attacker to potentially exploit memory corruption via a crafted PDF file.
0
Attacker Value
Unknown
CVE-2017-5121
Disclosure Date: October 27, 2017 (last updated November 08, 2023)
Inappropriate use of JIT optimisation in V8 in Google Chrome prior to 61.0.3163.100 for Linux, Windows, and Mac allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page, related to the escape analysis phase.
0