Show filters
508 Total Results
Displaying 291-300 of 508
Sort by:
Attacker Value
Unknown

CVE-2020-0558

Disclosure Date: April 15, 2020 (last updated November 27, 2024)
Improper buffer restrictions in kernel mode driver for Intel(R) PROSet/Wireless WiFi products before version 21.70 on Windows 10 may allow an unprivileged user to potentially enable denial of service via adjacent access.
Attacker Value
Unknown

CVE-2020-0557

Disclosure Date: April 15, 2020 (last updated February 21, 2025)
Insecure inherited permissions in Intel(R) PROSet/Wireless WiFi products before version 21.70 on Windows 10 may allow an authenticated user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2020-7606

Disclosure Date: March 15, 2020 (last updated February 21, 2025)
docker-compose-remote-api through 0.1.4 allows execution of arbitrary commands. Within 'index.js' of the package, the function 'exec(serviceName, cmd, fnStdout, fnStderr, fnExit)' uses the variable 'serviceName' which can be controlled by users without any sanitization.
Attacker Value
Unknown

CVE-2019-4429

Disclosure Date: February 18, 2020 (last updated February 21, 2025)
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162886.
Attacker Value
Unknown

CVE-2015-2909

Disclosure Date: February 06, 2020 (last updated February 21, 2025)
Dedicated Micros DV-IP Express, SD Advanced, SD, EcoSense, and DS2 devices rely on a GUI warning to help ensure that the administrator configures login credentials, which makes it easier for remote attackers to obtain access by leveraging situations in which this warning was not heeded. NOTE: the vendor states "The user is presented with clear warnings on the GUI that they should set usernames and passwords."
Attacker Value
Unknown

CVE-2012-6494

Disclosure Date: January 25, 2020 (last updated February 21, 2025)
Rapid7 Nexpose before 5.5.4 contains a session hijacking vulnerability which allows remote attackers to capture a user's session and gain unauthorized access.
Attacker Value
Unknown

CVE-2020-2563

Disclosure Date: January 15, 2020 (last updated November 27, 2024)
Vulnerability in the Hyperion Financial Close Management product of Oracle Hyperion (component: Close Manager). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Financial Close Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Hyperion Financial Close Management accessible data. CVSS 3.0 Base Score 4.2 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N).
Attacker Value
Unknown

CVE-2019-19307

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infinite loop), or possibly cause an out-of-bounds write, by sending a crafted MQTT protocol packet.
Attacker Value
Unknown

CVE-2013-6878

Disclosure Date: November 22, 2019 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in the Mijosoft MijoSearch component 2.0.4 and earlier for Joomla! allows remote attackers to inject arbitrary web script or HTML via the query parameter to component/mijosearch/search.
Attacker Value
Unknown

CVE-2013-6879

Disclosure Date: November 22, 2019 (last updated November 27, 2024)
The Mijosoft MijoSearch component 2.0.1 and earlier for Joomla! allows remote attackers to obtain sensitive information via a request to component/mijosearch/search, which reveals the installation path in an error message.