Show filters
87 Total Results
Displaying 31-40 of 87
Sort by:
Attacker Value
Unknown
CVE-2019-12897
Disclosure Date: June 19, 2019 (last updated November 27, 2024)
Edraw Max 7.9.3 has a Read Access Violation at the Instruction Pointer after a call from ObjectModule!Paint::Clear+0x0000000000000074.
0
Attacker Value
Unknown
CVE-2019-10735
Disclosure Date: April 07, 2019 (last updated November 27, 2024)
In Claws Mail 3.14.1, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to this (benign looking) email, they unknowingly leak the plaintext of the encrypted message part(s) back to the attacker.
0
Attacker Value
Unknown
CVE-2018-10245
Disclosure Date: April 20, 2018 (last updated November 26, 2024)
A Full Path Disclosure vulnerability in AWStats through 7.6 allows remote attackers to know where the config file is allocated, obtaining the full path of the server, a similar issue to CVE-2006-3682. The attack can, for example, use the awstats.pl framename and update parameters.
0
Attacker Value
Unknown
CVE-2018-7560
Disclosure Date: March 04, 2018 (last updated November 26, 2024)
index.js in the Anton Myshenin aws-lambda-multipart-parser NPM package before 0.1.2 has a Regular Expression Denial of Service (ReDoS) issue via a crafted multipart/form-data boundary string.
0
Attacker Value
Unknown
CVE-2017-1000501
Disclosure Date: January 03, 2018 (last updated November 26, 2024)
Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthenticated remote code execution.
0
Attacker Value
Unknown
CVE-2014-4978
Disclosure Date: December 29, 2017 (last updated November 26, 2024)
The rs_filter_graph function in librawstudio/rs-filter.c in rawstudio might allow local users to truncate arbitrary files via a symlink attack on (1) /tmp/rs-filter-graph.png or (2) /tmp/rs-filter-graph.
0
Attacker Value
Unknown
CVE-2017-10974
Disclosure Date: July 07, 2017 (last updated November 26, 2024)
Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an initial /%5C sequence to defeat traversal protection mechanisms; the initial /%5C sequence was apparently not discussed in earlier research on this product.
0
Attacker Value
Unknown
CVE-2015-8708
Disclosure Date: April 11, 2016 (last updated November 25, 2024)
Stack-based buffer overflow in the conv_euctojis function in codeconv.c in Claws Mail 3.13.1 allows remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8614.
0
Attacker Value
Unknown
CVE-2015-8614
Disclosure Date: April 11, 2016 (last updated November 08, 2023)
Multiple stack-based buffer overflows in the (1) conv_jistoeuc, (2) conv_euctojis, and (3) conv_sjistoeuc functions in codeconv.c in Claws Mail before 3.13.1 allow remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion.
0
Attacker Value
Unknown
CVE-2015-3373
Disclosure Date: April 21, 2015 (last updated October 05, 2023)
The Amazon AWS module before 7.x-1.3 for Drupal uses the base URL and AWS access key to generate the access token, which makes it easier for remote attackers to guess the token value and create backups via a crafted URL.
0