Show filters
564 Total Results
Displaying 391-400 of 564
Sort by:
Attacker Value
Unknown
CVE-2018-12551
Disclosure Date: March 27, 2019 (last updated November 27, 2024)
When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use a password file for authentication, any malformed data in the password file will be treated as valid. This typically means that the malformed data becomes a username and no password. If this occurs, clients can circumvent authentication and get access to the broker by using the malformed username. In particular, a blank line will be treated as a valid empty username. Other security measures are unaffected. Users who have only used the mosquitto_passwd utility to create and modify their password files are unaffected by this vulnerability.
0
Attacker Value
Unknown
CVE-2019-10231
Disclosure Date: March 27, 2019 (last updated November 27, 2024)
Teclib GLPI before 9.4.1.1 is affected by a PHP type juggling vulnerability allowing bypass of authentication. This occurs in Auth::checkPassword() (inc/auth.class.php).
0
Attacker Value
Unknown
CVE-2019-10232
Disclosure Date: March 27, 2019 (last updated November 27, 2024)
Teclib GLPI through 9.3.3 has SQL injection via the "cycle" parameter in /scripts/unlock_tasks.php.
0
Attacker Value
Unknown
CVE-2019-17635
Disclosure Date: March 22, 2019 (last updated February 21, 2025)
Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a deserialization vulnerability if an index file of a parsed heap dump is replaced by a malicious version and the heap dump is reopened in Memory Analyzer. The user must chose to reopen an already parsed heap dump with an untrusted index for the problem to occur. The problem can be averted if the index files from an untrusted source are deleted and the heap dump is opened and reparsed. Also some local configuration data is subject to a deserialization vulnerability if the local data were to be replaced with a malicious version. This can be averted if the local configuration data stored on the file system cannot be changed by an attacker. The vulnerability could possibly allow code execution on the local system.
0
Attacker Value
Unknown
CVE-2019-9004
Disclosure Date: February 22, 2019 (last updated November 27, 2024)
In Eclipse Wakaama (formerly liblwm2m) 1.0, core/er-coap-13/er-coap-13.c in lwm2mserver in the LWM2M server mishandles invalid options, leading to a memory leak. Processing of a single crafted packet leads to leaking (wasting) 24 bytes of memory. This can lead to termination of the LWM2M server after exhausting all available memory.
0
Attacker Value
Unknown
CVE-2018-12547
Disclosure Date: February 11, 2019 (last updated November 27, 2024)
In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects existing APIs that called the functions to exceed the allocated buffer. This functions were not directly callable by non-native user code.
0
Attacker Value
Unknown
CVE-2018-12549
Disclosure Date: February 11, 2019 (last updated November 27, 2024)
In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when accelerating it.
0
Attacker Value
Unknown
CVE-2018-12548
Disclosure Date: January 31, 2019 (last updated November 27, 2024)
In OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprovider.NativeCrypto class contains public static natives which accept pointer values that are dereferenced in the native code.
0
Attacker Value
Unknown
CVE-2019-5488
Disclosure Date: January 07, 2019 (last updated November 27, 2024)
EARCLINK ESPCMS-P8 has SQL injection in the install_pack/index.php?ac=Member&at=verifyAccount verify_key parameter. install_pack/espcms_public/espcms_db.php may allow retrieving sensitive information from the ESPCMS database.
0
Attacker Value
Unknown
CVE-2018-20227
Disclosure Date: December 19, 2018 (last updated August 17, 2024)
RDF4J 2.4.2 allows Directory Traversal via ../ in an entry in a ZIP archive.
0