Show filters
545 Total Results
Displaying 391-400 of 545
Sort by:
Attacker Value
Unknown
CVE-2015-4069
Disclosure Date: May 29, 2015 (last updated October 05, 2023)
The EdgeServiceImpl web service in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive credentials via a crafted SOAP request to the (1) getBackupPolicy or (2) getBackupPolicies method.
0
Attacker Value
Unknown
CVE-2015-4068
Disclosure Date: May 29, 2015 (last updated July 17, 2024)
Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) exportServlet servlet.
0
Attacker Value
Unknown
CVE-2015-2215
Disclosure Date: March 05, 2015 (last updated October 05, 2023)
Open redirect vulnerability in the Services single sign-on server helper (services_sso_server_helper) module for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified parameters.
0
Attacker Value
Unknown
CVE-2015-1164
Disclosure Date: January 21, 2015 (last updated October 05, 2023)
Open redirect vulnerability in the serve-static plugin before 1.7.2 for Node.js, when mounted at the root, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a // (slash slash) followed by a domain in the PATH_INFO to the default URI.
0
Attacker Value
Unknown
CVE-2014-8875
Disclosure Date: December 19, 2014 (last updated October 05, 2023)
The XML_RPC_cd function in lib/pear/XML/RPC.php in Revive Adserver before 3.0.6 allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted XML-RPC request, aka an XML Entity Expansion (XEE) attack.
0
Attacker Value
Unknown
CVE-2014-8793
Disclosure Date: December 19, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in lib/max/Admin/UI/Field/PublisherIdField.php in Revive Adserver before 3.0.6 allows remote attackers to inject arbitrary web script or HTML via the refresh_page parameter to www/admin/report-generate.php.
0
Attacker Value
Unknown
CVE-2014-9407
Disclosure Date: December 19, 2014 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Revive Adserver before 3.0.5 allow remote attackers to hijack the authentication of administrators for requests that (1) delete data via a request to agency-delete.php, (2) tracker-delete.php, or (3) userlog-delete.php in admin/ or (4) unlink accounts via a request to admin-user-unlink.php. (5) advertiser-user-unlink.php, or (6) affiliate-user-unlink.php in admin/.
0
Attacker Value
Unknown
CVE-2014-6052
Disclosure Date: December 15, 2014 (last updated October 05, 2023)
The HandleRFBServerMessage function in libvncclient/rfbproto.c in LibVNCServer 0.9.9 and earlier does not check certain malloc return values, which allows remote VNC servers to cause a denial of service (application crash) or possibly execute arbitrary code by specifying a large screen size in a (1) FramebufferUpdate, (2) ResizeFrameBuffer, or (3) PalmVNCReSizeFrameBuffer message.
0
Attacker Value
Unknown
CVE-2014-6053
Disclosure Date: December 15, 2014 (last updated October 05, 2023)
The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier does not properly handle attempts to send a large amount of ClientCutText data, which allows remote attackers to cause a denial of service (memory consumption or daemon crash) via a crafted message that is processed by using a single unchecked malloc.
0
Attacker Value
Unknown
CVE-2014-5425
Disclosure Date: October 19, 2014 (last updated October 05, 2023)
IOServer before Beta2112.exe allows remote attackers to cause a denial of service (out-of-bounds read and master entry consumption) via a null DNP3 header.
0