Show filters
116 Total Results
Displaying 41-50 of 116
Sort by:
Attacker Value
Unknown

CVE-2018-15865

Disclosure Date: September 06, 2018 (last updated November 27, 2024)
The Pulse Secure Desktop (macOS) has a Privilege Escalation Vulnerability.
0
Attacker Value
Unknown

CVE-2018-15749

Disclosure Date: September 06, 2018 (last updated November 27, 2024)
The Pulse Secure Desktop (macOS) 5.3RX before 5.3R5 and 9.0R1 has a Format String Vulnerability.
0
Attacker Value
Unknown

CVE-2018-15726

Disclosure Date: September 06, 2018 (last updated November 27, 2024)
The Pulse Secure Desktop (macOS) 5.3RX before 5.3R5 and 9.0R1 has a Privilege Escalation Vulnerability.
0
Attacker Value
Unknown

CVE-2018-16261

Disclosure Date: September 06, 2018 (last updated November 27, 2024)
In Pulse Secure Pulse Desktop Client 5.3RX before 5.3R5 and 9.0R1, there is a Privilege Escalation Vulnerability with Dynamic Certificate Trust.
0
Attacker Value
Unknown

CVE-2018-15911

Disclosure Date: August 28, 2018 (last updated November 08, 2023)
In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory access in the aesdecode operator to crash the interpreter or potentially execute code.
0
Attacker Value
Unknown

CVE-2018-15909

Disclosure Date: August 27, 2018 (last updated November 08, 2023)
In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to supply crafted PostScript files to crash the interpreter or potentially execute code.
0
Attacker Value
Unknown

CVE-2018-15910

Disclosure Date: August 27, 2018 (last updated November 08, 2023)
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the LockDistillerParams parameter to crash the interpreter or execute code.
0
Attacker Value
Unknown

CVE-2018-8032

Disclosure Date: August 02, 2018 (last updated November 08, 2023)
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
Attacker Value
Unknown

CVE-2018-3639

Disclosure Date: May 22, 2018 (last updated November 26, 2024)
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.
Attacker Value
Unknown

CVE-2018-1304

Disclosure Date: February 28, 2018 (last updated December 09, 2023)
The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.
0