Show filters
400 Total Results
Displaying 331-340 of 400
Sort by:
Attacker Value
Unknown

CVE-2015-1027

Disclosure Date: September 29, 2017 (last updated November 26, 2024)
The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HTTP downgrade attacks and Man In The Middle attacks in which the server response could be modified to allow the attacker to respond with modified command payload and have the client return additional running configuration information leading to an information disclosure of running configuration of MySQL.
0
Attacker Value
Unknown

CVE-2014-2029

Disclosure Date: September 29, 2017 (last updated November 26, 2024)
The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obtain sensitive information or execute arbitrary code by leveraging use of HTTP to download configuration information from v.percona.com.
0
Attacker Value
Unknown

CVE-2017-9149

Disclosure Date: May 22, 2017 (last updated November 26, 2024)
Metadata Anonymisation Toolkit (MAT) 0.6 and 0.6.1 silently fails to perform "Clean metadata" actions upon invocation from the Nautilus contextual menu, which allows context-dependent attackers to obtain sensitive information by reading a file for which cleaning had been attempted.
0
Attacker Value
Unknown

CVE-2017-7584

Disclosure Date: April 07, 2017 (last updated November 26, 2024)
Memory Corruption Vulnerability in Foxit PDF Toolkit before 2.1 allows an attacker to cause Denial of Service & Remote Code Execution when a victim opens a specially crafted PDF file.
0
Attacker Value
Unknown

CVE-2017-5364

Disclosure Date: January 13, 2017 (last updated November 25, 2024)
Memory Corruption Vulnerability in Foxit PDF Toolkit v1.3 allows an attacker to cause Denial of Service and Remote Code Execution when the victim opens the specially crafted PDF file. The Vulnerability has been fixed in v2.0.
0
Attacker Value
Unknown

CVE-2016-5109

Disclosure Date: July 13, 2016 (last updated November 25, 2024)
Citrix Worx Home for iOS before 10.3.6 and XenMobile MDX Toolkit for iOS before 10.3.6 might allow physically proximate attackers to bypass in-application Apple Touch ID authentication via unspecified vectors, related to an application requiring re-authentication.
0
Attacker Value
Unknown

CVE-2016-4216

Disclosure Date: July 13, 2016 (last updated November 25, 2024)
XMPCore in Adobe XMP Toolkit for Java before 5.1.3 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
0
Attacker Value
Unknown

CVE-2015-5508

Disclosure Date: August 18, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the XC NCIP Provider module in the eXtensible Catalog (XC) Drupal Toolkit allows remote attackers to hijack the authentication of users with the "administer ncip providers" permission for requests that alter NCIP providers via a crafted request.
0
Attacker Value
Unknown

CVE-2015-4670

Disclosure Date: August 18, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in the AjaxFileUpload control in DevExpress AJAX Control Toolkit (aka AjaxControlToolkit) before 15.1 allows remote attackers to write to arbitrary files via a .. (dot dot) in the fileId parameter to AjaxFileUploadHandler.axd.
0
Attacker Value
Unknown

CVE-2014-1420

Disclosure Date: July 24, 2014 (last updated February 22, 2025)
On desktop, Ubuntu UI Toolkit's StateSaver would serialise data on tmp/ files which an attacker could use to expose potentially sensitive data. StateSaver would also open files without the O_EXCL flag. An attacker could exploit this to launch a symlink attack, though this is partially mitigated by symlink and hardlink restrictions in Ubuntu. Fixed in 1.1.1188+14.10.20140813.4-0ubuntu1.