Show filters
1,081 Total Results
Displaying 301-310 of 1,081
Sort by:
Attacker Value
Unknown
CVE-2015-2003
Disclosure Date: March 29, 2018 (last updated November 26, 2024)
The PJSIP PJSUA2 SDK before SVN Changeset 51322 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.
0
Attacker Value
Unknown
CVE-2018-3626
Disclosure Date: March 20, 2018 (last updated November 26, 2024)
Edger8r tool in the Intel SGX SDK before version 2.1.2 (Linux) and 1.9.6 (Windows) may generate code that is susceptible to a side channel potentially allowing a local user to access unauthorized information.
0
Attacker Value
Unknown
CVE-2018-1000134
Disclosure Date: March 16, 2018 (last updated November 26, 2024)
UnboundID LDAP SDK version from commit 801111d8b5c732266a5dbd4b3bb0b6c7b94d7afb up to commit 8471904a02438c03965d21367890276bc25fa5a6, where the issue was reported and fixed contains an Incorrect Access Control vulnerability in process function in SimpleBindRequest class doesn't check for empty password when running in synchronous mode. commit with applied fix https://github.com/pingidentity/ldapsdk/commit/8471904a02438c03965d21367890276bc25fa5a6#diff-f6cb23b459be1ec17df1da33760087fd that can result in Ability to impersonate any valid user. This attack appear to be exploitable via Providing valid username and empty password against servers that do not do additional validation as per https://tools.ietf.org/html/rfc4513#section-5.1.1. This vulnerability appears to have been fixed in after commit 8471904a02438c03965d21367890276bc25fa5a6.
0
Attacker Value
Unknown
CVE-2017-17428
Disclosure Date: March 05, 2018 (last updated November 26, 2024)
Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.
0
Attacker Value
Unknown
CVE-2018-1417
Disclosure Date: February 22, 2018 (last updated November 26, 2024)
Under certain circumstances, a flaw in the J9 JVM (IBM SDK, Java Technology Edition 7.1 and 8.0) allows untrusted code running under a security manager to elevate its privileges. IBM X-Force ID: 138823.
0
Attacker Value
Unknown
CVE-2018-1000025
Disclosure Date: February 09, 2018 (last updated November 26, 2024)
Jerome Gamez Firebase Admin SDK for PHP version from 3.2.0 to 3.8.0 contains a Incorrect Access Control vulnerability in src/Firebase/Auth/IdTokenVerifier.php does not verify for token signature that can result in JWT with any email address and user ID could be forged from an actual token, or from thin air. This attack appear to be exploitable via Attacker would only need to know email address of the victim on most cases.. This vulnerability appears to have been fixed in 3.8.1.
0
Attacker Value
Unknown
CVE-2018-6462
Disclosure Date: January 31, 2018 (last updated November 26, 2024)
Tracker PDF-XChange Viewer and Viewer AX SDK before 2.5.322.8 mishandle conversion from YCC to RGB colour spaces by calculating on the basis of 1 bpc instead of 8 bpc, which might allow remote attackers to execute arbitrary code via a crafted PDF document.
0
Attacker Value
Unknown
CVE-2017-14378
Disclosure Date: November 29, 2017 (last updated November 26, 2024)
EMC RSA Authentication Agent API 8.5 for C and RSA Authentication Agent SDK 8.6 for C allow attackers to bypass authentication, aka an "Error Handling Vulnerability."
0
Attacker Value
Unknown
CVE-2017-16665
Disclosure Date: November 08, 2017 (last updated November 26, 2024)
RemObjects Remoting SDK 9 1.0.0.0 for Delphi is vulnerable to a reflected Cross Site Scripting (XSS) attack via the service parameter to the /soap URI, triggering an invalid attempt to generate WSDL.
0
Attacker Value
Unknown
CVE-2014-8889
Disclosure Date: September 26, 2017 (last updated November 26, 2024)
Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or via a drive-by download attack.
0