Show filters
545 Total Results
Displaying 391-400 of 545
Sort by:
Attacker Value
Unknown

CVE-2018-14840

Disclosure Date: August 02, 2018 (last updated November 27, 2024)
uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for example, .htm file uploads).
0
Attacker Value
Unknown

CVE-2018-14835

Disclosure Date: August 02, 2018 (last updated November 27, 2024)
Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed in multiple areas.
0
Attacker Value
Unknown

CVE-2018-14836

Disclosure Date: August 02, 2018 (last updated November 27, 2024)
Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able to access it (but not perform actions) if the Guests user group has access to the Admin panel.
0
Attacker Value
Unknown

CVE-2018-2907

Disclosure Date: July 18, 2018 (last updated November 27, 2024)
Vulnerability in the Hyperion Financial Reporting component of Oracle Hyperion (subcomponent: Security Models). The supported version that is affected is 11.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Financial Reporting. While the vulnerability is in Hyperion Financial Reporting, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Hyperion Financial Reporting accessible data. CVSS 3.0 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
0
Attacker Value
Unknown

CVE-2018-2915

Disclosure Date: July 18, 2018 (last updated November 27, 2024)
Vulnerability in the Hyperion Data Relationship Management component of Oracle Hyperion (subcomponent: Access and security). The supported version that is affected is 11.1.2.4.330. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Hyperion Data Relationship Management. While the vulnerability is in Hyperion Data Relationship Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Hyperion Data Relationship Management accessible data. CVSS 3.0 Base Score 5.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N).
0
Attacker Value
Unknown

CVE-2018-13068

Disclosure Date: July 03, 2018 (last updated November 26, 2024)
The mintToken function of a smart contract implementation for AzurionToken (AZU), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
0
Attacker Value
Unknown

CVE-2016-10648

Disclosure Date: June 04, 2018 (last updated November 26, 2024)
marionette-socket-host is a marionette-js-runner host for sending actions over a socket. marionette-socket-host downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.
0
Attacker Value
Unknown

CVE-2016-10527

Disclosure Date: May 31, 2018 (last updated November 26, 2024)
The riot-compiler version version 2.3.21 has an issue in a regex (Catastrophic Backtracking) thats make it unusable under certain conditions.
0
Attacker Value
Unknown

CVE-2018-6292

Disclosure Date: February 13, 2018 (last updated November 26, 2024)
Remote Code Execution in Saperion Web Client version 7.5.2 83166.
0
Attacker Value
Unknown

CVE-2018-6293

Disclosure Date: February 13, 2018 (last updated November 26, 2024)
Arbitrary File Read in Saperion Web Client version 7.5.2 83166.
0