Show filters
501 Total Results
Displaying 381-390 of 501
Sort by:
Attacker Value
Unknown
CVE-2013-6427
Disclosure Date: December 09, 2013 (last updated October 05, 2023)
upgrade.py in the hp-upgrade service in HP Linux Imaging and Printing (HPLIP) 3.x through 3.13.11 launches a program from an http URL, which allows man-in-the-middle attackers to execute arbitrary code by gaining control over the client-server data stream.
0
Attacker Value
Unknown
CVE-2013-3281
Disclosure Date: November 06, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in EMC Documentum Webtop before 6.7 SP2 P07, Documentum WDK before 6.7 SP2 P07, Documentum Taskspace before 6.7 SP2 P07, Documentum Records Manager before 6.7 SP2 P07, Documentum Web Publisher before 6.5 SP7, Documentum Digital Asset Manager before 6.5 SP6, Documentum Administrator before 6.7 SP2 P07, and Documentum Capital Projects before 1.8 P01 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter in a URL.
0
Attacker Value
Unknown
CVE-2013-4325
Disclosure Date: September 23, 2013 (last updated October 05, 2023)
The check_permission_v1 function in base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.9 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process.
0
Attacker Value
Unknown
CVE-2013-0200
Disclosure Date: March 06, 2013 (last updated October 05, 2023)
HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/hpcups_job#.out, (4) /tmp/hpijs_#####.out, or (5) /tmp/hpps_job#.out temporary file, a different vulnerability than CVE-2011-2722.
0
Attacker Value
Unknown
CVE-2012-5352
Disclosure Date: October 09, 2012 (last updated October 05, 2023)
Java Open Single Sign-On Project Home (JOSSO) allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack."
0
Attacker Value
Unknown
CVE-2012-3137
Disclosure Date: September 21, 2012 (last updated October 05, 2023)
The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and makes it easier to conduct brute force password guessing attacks, aka "stealth password cracking vulnerability."
0
Attacker Value
Unknown
CVE-2010-5223
Disclosure Date: September 06, 2012 (last updated October 05, 2023)
Multiple untrusted search path vulnerabilities in Phoenix Project Manager 2.1.0.8 allow local users to gain privileges via a Trojan horse (1) wbtrv32.dll or (2) w3btrv7.dll file in the current working directory, as demonstrated by a directory that contains a .ppx file. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2011-2722
Disclosure Date: May 25, 2012 (last updated October 04, 2023)
The send_data_to_stdout function in prnt/hpijs/hpcupsfax.cpp in HP Linux Imaging and Printing (HPLIP) 3.x before 3.11.10 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/hpcupsfax.out temporary file.
0
Attacker Value
Unknown
CVE-2012-1027
Disclosure Date: February 08, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in account-closed.tcl in ]project-open[ (aka ]po[) 3.4.x, 3.5.0.1-2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the message parameter to register/account-closed.
0
Attacker Value
Unknown
CVE-2011-4277
Disclosure Date: November 03, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in CourseForum ProjectForum 7.0.1.3038 allows remote attackers to inject arbitrary web script or HTML via a crafted name of an object within a more object on a wiki page.
0