Show filters
1,081 Total Results
Displaying 291-300 of 1,081
Sort by:
Attacker Value
Unknown

CVE-2016-10603

Disclosure Date: June 01, 2018 (last updated November 26, 2024)
air-sdk is a NPM wrapper for the Adobe AIR SDK. air-sdk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.
0
Attacker Value
Unknown

CVE-2016-10587

Disclosure Date: June 01, 2018 (last updated November 26, 2024)
wasdk is a toolkit for creating WebAssembly modules. wasdk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.
0
Attacker Value
Unknown

CVE-2016-10590

Disclosure Date: May 29, 2018 (last updated November 26, 2024)
cue-sdk-node is a Corsair Cue SDK wrapper for node.js. cue-sdk-node downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested zip file with an attacker controlled zip file if the attacker is on the network or positioned in between the user and the remote server.
0
Attacker Value
Unknown

CVE-2017-2811

Disclosure Date: April 24, 2018 (last updated November 26, 2024)
A code execution vulnerability exists in the Kakadu SDK 7.9's parsing of compressed JPEG 2000 images. A specially crafted JPEG 2000 file can be read by the program, and can lead to an out of bounds write causing an exploitable condition to arise.
0
Attacker Value
Unknown

CVE-2017-2812

Disclosure Date: April 24, 2018 (last updated November 26, 2024)
A code execution vulnerability exists in the kdu_buffered_expand function of the Kakadu SDK 7.9. A specially crafted JPEG 2000 file can be read by the program and can lead to an out of bounds write causing an exploitable condition to arise.
0
Attacker Value
Unknown

CVE-2016-8365

Disclosure Date: April 03, 2018 (last updated November 26, 2024)
OSIsoft PI System software (Applications using PI Asset Framework (AF) Client versions prior to PI AF Client 2016, Version 2.8.0; Applications using PI Software Development Kit (SDK) versions prior to PI SDK 2016, Version 1.4.6; PI Buffer Subsystem, versions prior to and including, Version 4.4; and PI Data Archive versions prior to PI Data Archive 2015, Version 3.4.395.64) operates between endpoints without a complete model of endpoint features potentially causing the product to perform actions based on this incomplete model, which could result in a denial of service. OSIsoft reports that in order to exploit the vulnerability an attacker would need to be locally connected to a server. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H)
0
Attacker Value
Unknown

CVE-2015-2000

Disclosure Date: March 29, 2018 (last updated November 26, 2024)
The Jumio SDK before 1.5.0 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.
0
Attacker Value
Unknown

CVE-2015-2001

Disclosure Date: March 29, 2018 (last updated November 26, 2024)
The MetaIO SDK before 6.0.2.1 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.
0
Attacker Value
Unknown

CVE-2015-2004

Disclosure Date: March 29, 2018 (last updated November 26, 2024)
The GraceNote GNSDK SDK before SVN Changeset 1.1.7 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.
0
Attacker Value
Unknown

CVE-2015-2002

Disclosure Date: March 29, 2018 (last updated November 26, 2024)
The ESRI ArcGis Runtime SDK before 10.2.6-2 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.
0