Show filters
649 Total Results
Displaying 291-300 of 649
Sort by:
Attacker Value
Unknown
CVE-2015-5173
Disclosure Date: October 24, 2017 (last updated November 26, 2024)
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact via vectors involving emails with password recovery links, aka "Cross Domain Referer Leakage."
0
Attacker Value
Unknown
CVE-2015-5170
Disclosure Date: October 24, 2017 (last updated November 26, 2024)
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct cross-site request forgery (CSRF) attacks on PWS and log a user into an arbitrary account by leveraging lack of CSRF checks.
0
Attacker Value
Unknown
CVE-2015-5172
Disclosure Date: October 24, 2017 (last updated November 26, 2024)
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire password reset links.
0
Attacker Value
Unknown
CVE-2017-12613
Disclosure Date: October 24, 2017 (last updated November 08, 2023)
When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially revealing the contents of a different static heap value or resulting in program termination, and may represent an information disclosure or denial of service vulnerability to applications which call these APR functions with unvalidated external input.
0
Attacker Value
Unknown
CVE-2017-12618
Disclosure Date: October 24, 2017 (last updated November 26, 2024)
Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access. A local user with write access to the database can make a program or process using these functions crash, and cause a denial of service.
0
Attacker Value
Unknown
CVE-2017-11292
Disclosure Date: October 22, 2017 (last updated November 26, 2024)
Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitation could lead to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2016-0732
Disclosure Date: September 07, 2017 (last updated November 26, 2024)
The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allows remote authenticated users with privileges in one zone to gain privileges and perform operations on a different zone via unspecified vectors.
0
Attacker Value
Unknown
CVE-2017-3106
Disclosure Date: August 11, 2017 (last updated November 26, 2024)
Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files. Successful exploitation could lead to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2017-3085
Disclosure Date: August 11, 2017 (last updated November 26, 2024)
Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redirect.
0
Attacker Value
Unknown
CVE-2017-3099
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
Adobe Flash Player versions 26.0.0.131 and earlier have an exploitable memory corruption vulnerability in the Action Script 3 raster data model. Successful exploitation could lead to arbitrary code execution.
0