Show filters
563 Total Results
Displaying 341-350 of 563
Sort by:
Attacker Value
Unknown

CVE-2020-9352

Disclosure Date: February 23, 2020 (last updated February 21, 2025)
An issue was discovered in SmartClient 12.0. Unauthenticated exploitation of blind XXE can occur in the downloadWSDL feature by sending a POST request to /tools/developerConsoleOperations.jsp with a valid payload in the _transaction parameter. NOTE: the documentation states "These tools are, by default, available to anyone ... so they should only be deployed into a trusted environment. Alternately, the tools can easily be restricted to administrators or end users by protecting the tools path with normal authentication and authorization mechanisms on the web server."
Attacker Value
Unknown

CVE-2020-9351

Disclosure Date: February 23, 2020 (last updated February 21, 2025)
An issue was discovered in SmartClient 12.0. If an unauthenticated attacker makes a POST request to /tools/developerConsoleOperations.jsp or /isomorphic/IDACall with malformed XML data in the _transaction parameter, the server replies with a verbose error showing where the application resides (the absolute path). NOTE: the documentation states "These tools are, by default, available to anyone ... so they should only be deployed into a trusted environment. Alternately, the tools can easily be restricted to administrators or end users by protecting the tools path with normal authentication and authorization mechanisms on the web server."
Attacker Value
Unknown

CVE-2014-9390

Disclosure Date: February 12, 2020 (last updated February 21, 2025)
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem.
Attacker Value
Unknown

CVE-2019-17634

Disclosure Date: January 17, 2020 (last updated February 21, 2025)
Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a cross site scripting (XSS) vulnerability when generating an HTML report from a malicious heap dump. The user must chose todownload, open the malicious heap dump and generate an HTML report for the problem to occur. The heap dump could be specially crafted, or could come from a crafted application or from an application processing malicious data. The vulnerability is present whena report is generated and opened from the Memory Analyzer graphical user interface, or when a report generated in batch mode is then opened in Memory Analyzer or by a web browser. The vulnerability could possibly allow code execution on the local system whenthe report is opened in Memory Analyzer.
Attacker Value
Unknown

CVE-2014-9211

Disclosure Date: January 14, 2020 (last updated February 21, 2025)
ClickDesk version 4.3 and below has persistent cross site scripting
Attacker Value
Unknown

CVE-2019-17633

Disclosure Date: December 19, 2019 (last updated November 27, 2024)
For Eclipse Che versions 6.16 to 7.3.0, with both authentication and TLS disabled, visiting a malicious web site could trigger the start of an arbitrary Che workspace. Che with no authentication and no TLS is not usually deployed on a public network but is often used for local installations (e.g. on personal laptops). In that case, even if the Che API is not exposed externally, some javascript running in the local browser is able to send requests to it.
Attacker Value
Unknown

CVE-2012-2248

Disclosure Date: November 27, 2019 (last updated November 27, 2024)
An issue was discovered in dhclient 4.3.1-6 due to an embedded path variable.
Attacker Value
Unknown

CVE-2019-17632

Disclosure Date: November 25, 2019 (last updated November 08, 2023)
In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.
Attacker Value
Unknown

CVE-2019-3465

Disclosure Date: November 07, 2019 (last updated November 08, 2023)
Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate others or elevate privileges by creating a crafted XML message.
Attacker Value
Unknown

CVE-2009-5045

Disclosure Date: November 06, 2019 (last updated November 27, 2024)
Dump Servlet information leak in jetty before 6.1.22.