Show filters
602 Total Results
Displaying 421-430 of 602
Sort by:
Attacker Value
Unknown
CVE-2018-4397
Disclosure Date: April 03, 2019 (last updated November 27, 2024)
Analytics data was sent using HTTP rather than HTTPS. This was addressed by sending analytics data using HTTPS. This issue affected versions prior to Apple Support 2.4 for iOS.
0
Attacker Value
Unknown
CVE-2018-5927
Disclosure Date: March 27, 2019 (last updated November 27, 2024)
HP Support Assistant before 8.7.50.3 allows an unauthorized person with local access to load arbitrary code.
0
Attacker Value
Unknown
CVE-2019-7299
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Ticket System plugin 9.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the subject parameter in wp-content/plugins/wp-support-plus-responsive-ticket-system/includes/ajax/submit_ticket.php.
0
Attacker Value
Unknown
Local root exploit via inclusion of attacker controlled shell script
Disclosure Date: March 05, 2019 (last updated November 08, 2023)
Supportutils, before version 3.1-5.7.1, when run with command line argument -A searched the file system for a ndspath binary. If an attacker provides one at an arbitrary location it is executed with root privileges
0
Attacker Value
Unknown
User can overwrite arbitrary log files in support tar
Disclosure Date: March 05, 2019 (last updated November 08, 2023)
In supportutils, before version 3.1-5.7.1 and if pacemaker is installed on the system, an unprivileged user could have overwritten arbitrary files in the directory that is used by supportutils to collect the log files.
0
Attacker Value
Unknown
Code execution if run with command line switch -v
Disclosure Date: March 05, 2019 (last updated November 08, 2023)
If supportutils before version 3.1-5.7.1 is run with -v to perform rpm verification and the attacker manages to manipulate the rpm listing (e.g. with CVE-2018-19638) he can execute arbitrary commands as root.
0
Attacker Value
Unknown
Static temporary filename allows overwriting of files
Disclosure Date: March 05, 2019 (last updated November 08, 2023)
Supportutils, before version 3.1-5.7.1, wrote data to static file /tmp/supp_log, allowing local attackers to overwrite files on systems without symlink protection
0
Attacker Value
Unknown
Code execution if run with command line switch -v
Disclosure Date: March 05, 2019 (last updated November 08, 2023)
If the attacker manages to create files in the directory used to collect log files in supportutils before version 3.1-5.7.1 (e.g. with CVE-2018-19638) he can kill arbitrary processes on the local machine.
0
Attacker Value
Unknown
CVE-2019-16576
Disclosure Date: January 24, 2019 (last updated October 26, 2023)
A missing permission check in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing the Kubernetes service account token or credentials stored in Jenkins.
0
Attacker Value
Unknown
CVE-2019-0088
Disclosure Date: January 10, 2019 (last updated November 27, 2024)
Insufficient path checking in Intel(R) System Support Utility for Windows before 2.5.0.15 may allow an authenticated user to potentially enable an escalation of privilege via local access.
0