Show filters
67 Total Results
Displaying 41-50 of 67
Sort by:
Attacker Value
Unknown
CVE-2018-10388
Disclosure Date: December 23, 2019 (last updated November 27, 2024)
Format string vulnerability in the logMess function in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet.
0
Attacker Value
Unknown
CVE-2014-2387
Disclosure Date: December 13, 2019 (last updated November 27, 2024)
Pen 0.18.0 has Insecure Temporary File Creation vulnerabilities
0
Attacker Value
Unknown
CVE-2019-12568
Disclosure Date: September 11, 2019 (last updated November 27, 2024)
Stack-based overflow vulnerability in the logMess function in Open TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2018-10387 and CVE-2019-12567.
0
Attacker Value
Unknown
CVE-2018-18758
Disclosure Date: June 19, 2019 (last updated November 27, 2024)
Open Faculty Evaluation System 7 for PHP 7 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18757.
0
Attacker Value
Unknown
CVE-2018-18757
Disclosure Date: June 19, 2019 (last updated November 27, 2024)
Open Faculty Evaluation System 5.6 for PHP 5.6 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18758.
0
Attacker Value
Unknown
CVE-2018-16457
Disclosure Date: October 04, 2018 (last updated February 15, 2024)
PHP Scripts Mall Open Source Real-estate Script 3.6.2 allows remote attackers to list the wp-content/themes/template_dp_dec2015/img directory.
0
Attacker Value
Unknown
CVE-2017-16187
Disclosure Date: June 07, 2018 (last updated November 26, 2024)
open-device creates a web interface for any device. open-device is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
0
Attacker Value
Unknown
CVE-2018-10389
Disclosure Date: April 02, 2018 (last updated November 27, 2024)
Format string vulnerability in the logMess function in TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet.
0
Attacker Value
Unknown
CVE-2014-9504
Disclosure Date: February 01, 2018 (last updated November 26, 2024)
The OG Subgroups module, when used with the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal, allows remote attackers to access child groups via vectors related to membership inheritance.
0
Attacker Value
Unknown
CVE-2014-9503
Disclosure Date: February 01, 2018 (last updated November 26, 2024)
The Discussions sub module in the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal allows remote authenticated users with "access content" permissions to modify arbitrary nodes by leveraging improper access checks on unspecified ajax callbacks.
0