Show filters
110 Total Results
Displaying 41-50 of 110
Sort by:
Attacker Value
Unknown

CVE-2018-8865

Disclosure Date: May 04, 2018 (last updated November 26, 2024)
In Lantech IDS 2102 2.0 and prior, a stack-based buffer overflow vulnerability has been identified which may allow remote code execution. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Attacker Value
Unknown

TIBCO DataSynapse GridServer manager component vulnerable to cross-site scripti…

Disclosure Date: May 01, 2018 (last updated November 26, 2024)
The GridServer Broker, and GridServer Director components of TIBCO Software Inc. TIBCO DataSynapse GridServer Manager contain vulnerabilities which may allow an authenticated user to perform cross-site scripting (XSS). In addition, an authenticated user could be a victim of a cross-site request forgery (CSRF) attack. Affected releases include TIBCO Software Inc.'s TIBCO DataSynapse GridServer Manager: versions up to and including 5.1.3; 6.0.0; 6.0.1; 6.0.2; 6.1.0; 6.1.1; and 6.2.0.
0
Attacker Value
Unknown

TIBCO DataSynapse GridServer improper use of encryption

Disclosure Date: May 01, 2018 (last updated November 26, 2024)
The GridServer Broker, GridServer Driver, and GridServer Engine components of TIBCO Software Inc. TIBCO DataSynapse GridServer Manager contain vulnerabilities related to both the improper use of encryption mechanisms and the use of weak ciphers. A malicious actor could theoretically compromise the traffic between any of the components. Affected releases include TIBCO Software Inc.'s TIBCO DataSynapse GridServer Manager: versions up to and including 5.1.3; 6.0.0; 6.0.1; 6.0.2; 6.1.0; 6.1.1; and 6.2.0.
0
Attacker Value
Unknown

CVE-2017-1000498

Disclosure Date: January 03, 2018 (last updated November 26, 2024)
AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution
Attacker Value
Unknown

CVE-2017-17581

Disclosure Date: December 13, 2017 (last updated November 26, 2024)
FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter.
Attacker Value
Unknown

CVE-2017-2225

Disclosure Date: July 07, 2017 (last updated November 26, 2024)
Untrusted search path vulnerability in EbidSettingChecker.exe (version 1.0.0.0) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
0
Attacker Value
Unknown

CVE-2016-7089

Disclosure Date: August 24, 2016 (last updated November 25, 2024)
WatchGuard RapidStream appliances allow local users to gain privileges and execute arbitrary commands via a crafted ifconfig command, aka ESCALATEPLOWMAN.
0
Attacker Value
Unknown

CVE-2014-7376

Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Facebook Profits on Steroids (aka com.wFacebookProfitsonSteroids) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-6973

Disclosure Date: October 16, 2014 (last updated October 05, 2023)
The Care4Kids (aka com.codetherapy.care4kids) application 1.03 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-7021

Disclosure Date: October 16, 2014 (last updated October 05, 2023)
The Leg Surgery - Kids Games (aka com.harriskerioe.legsurgery) application 1.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0