Show filters
65 Total Results
Displaying 31-40 of 65
Sort by:
Attacker Value
Unknown

CVE-2014-3038

Disclosure Date: June 08, 2014 (last updated October 05, 2023)
IBM SPSS Modeler 16.0 before 16.0.0.1 on UNIX does not properly drop group privileges, which allows local users to bypass intended file-access restrictions by leveraging (1) gid 0 or (2) root's group memberships.
0
Attacker Value
Unknown

CVE-2014-0920

Disclosure Date: April 10, 2014 (last updated October 05, 2023)
IBM SPSS Analytic Server 1.0 before IF002 and 1.0.1 before IF004 logs cleartext passwords, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-0895

Disclosure Date: March 16, 2014 (last updated October 05, 2023)
Buffer overflow in the vsflex8l ActiveX control in IBM SPSS SamplePower 3.0.1 before FP1 3.0.1-IM-S3SAMPC-WIN32-FP001-IF02 allows remote attackers to execute arbitrary code via a crafted ComboList property value.
0
Attacker Value
Unknown

CVE-2013-6724

Disclosure Date: February 01, 2014 (last updated October 05, 2023)
Unspecified vulnerability in the vsflex8l ActiveX control in IBM SPSS SamplePower 3.0.1 before FP1 IF1 allows remote attackers to execute arbitrary code via a crafted ComboList property value.
0
Attacker Value
Unknown

CVE-2013-4043

Disclosure Date: February 01, 2014 (last updated October 05, 2023)
The server in IBM SPSS Collaboration and Deployment Services 4.x before 4.2.1.3 IF3, 5.x before 5.0 FP3, and 6.x before 6.0 IF1 allows remote attackers to read arbitrary files via an unspecified HTTP request.
0
Attacker Value
Unknown

CVE-2013-4044

Disclosure Date: December 21, 2013 (last updated October 05, 2023)
IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote authenticated users to read application log files via a direct HTTP request.
0
Attacker Value
Unknown

CVE-2013-4045

Disclosure Date: December 21, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-4069

Disclosure Date: December 21, 2013 (last updated October 05, 2023)
The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
0
Attacker Value
Unknown

CVE-2013-4070

Disclosure Date: December 21, 2013 (last updated October 05, 2023)
The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to discover an internal password via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-4046

Disclosure Date: December 21, 2013 (last updated October 05, 2023)
Open redirect vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
0