Show filters
110 Total Results
Displaying 41-50 of 110
Sort by:
Attacker Value
Unknown
CVE-2018-8865
Disclosure Date: May 04, 2018 (last updated November 26, 2024)
In Lantech IDS 2102 2.0 and prior, a stack-based buffer overflow vulnerability has been identified which may allow remote code execution. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
0
Attacker Value
Unknown
TIBCO DataSynapse GridServer manager component vulnerable to cross-site scripti…
Disclosure Date: May 01, 2018 (last updated November 26, 2024)
The GridServer Broker, and GridServer Director components of TIBCO Software Inc. TIBCO DataSynapse GridServer Manager contain vulnerabilities which may allow an authenticated user to perform cross-site scripting (XSS). In addition, an authenticated user could be a victim of a cross-site request forgery (CSRF) attack. Affected releases include TIBCO Software Inc.'s TIBCO DataSynapse GridServer Manager: versions up to and including 5.1.3; 6.0.0; 6.0.1; 6.0.2; 6.1.0; 6.1.1; and 6.2.0.
0
Attacker Value
Unknown
TIBCO DataSynapse GridServer improper use of encryption
Disclosure Date: May 01, 2018 (last updated November 26, 2024)
The GridServer Broker, GridServer Driver, and GridServer Engine components of TIBCO Software Inc. TIBCO DataSynapse GridServer Manager contain vulnerabilities related to both the improper use of encryption mechanisms and the use of weak ciphers. A malicious actor could theoretically compromise the traffic between any of the components. Affected releases include TIBCO Software Inc.'s TIBCO DataSynapse GridServer Manager: versions up to and including 5.1.3; 6.0.0; 6.0.1; 6.0.2; 6.1.0; 6.1.1; and 6.2.0.
0
Attacker Value
Unknown
CVE-2017-1000498
Disclosure Date: January 03, 2018 (last updated November 26, 2024)
AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution
0
Attacker Value
Unknown
CVE-2017-17581
Disclosure Date: December 13, 2017 (last updated November 26, 2024)
FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter.
0
Attacker Value
Unknown
CVE-2017-2225
Disclosure Date: July 07, 2017 (last updated November 26, 2024)
Untrusted search path vulnerability in EbidSettingChecker.exe (version 1.0.0.0) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
0
Attacker Value
Unknown
CVE-2016-7089
Disclosure Date: August 24, 2016 (last updated November 25, 2024)
WatchGuard RapidStream appliances allow local users to gain privileges and execute arbitrary commands via a crafted ifconfig command, aka ESCALATEPLOWMAN.
0
Attacker Value
Unknown
CVE-2014-7376
Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Facebook Profits on Steroids (aka com.wFacebookProfitsonSteroids) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-6973
Disclosure Date: October 16, 2014 (last updated October 05, 2023)
The Care4Kids (aka com.codetherapy.care4kids) application 1.03 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-7021
Disclosure Date: October 16, 2014 (last updated October 05, 2023)
The Leg Surgery - Kids Games (aka com.harriskerioe.legsurgery) application 1.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0