Show filters
545 Total Results
Displaying 431-440 of 545
Sort by:
Attacker Value
Unknown
CVE-2016-2788
Disclosure Date: February 13, 2017 (last updated November 26, 2024)
MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the mco ping command.
0
Attacker Value
Unknown
CVE-2017-5543
Disclosure Date: January 20, 2017 (last updated November 25, 2024)
includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data in a salt cookie in a login request.
0
Attacker Value
Unknown
CVE-2016-6580
Disclosure Date: January 10, 2017 (last updated November 25, 2024)
A HTTP/2 implementation built using any version of the Python priority library prior to version 1.2.0 could be targeted by a malicious peer by having that peer assign priority information for every possible HTTP/2 stream ID. The priority tree would happily continue to store the priority information for each stream, and would therefore allocate unbounded amounts of memory. Attempting to actually use a tree like this would also cause extremely high CPU usage to maintain the tree.
0
Attacker Value
Unknown
CVE-2016-3493
Disclosure Date: July 21, 2016 (last updated November 25, 2024)
Unspecified vulnerability in the Hyperion Financial Reporting component in Oracle Hyperion 11.1.2.4 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Security Models.
0
Attacker Value
Unknown
CVE-2016-4328
Disclosure Date: June 10, 2016 (last updated November 25, 2024)
MEDHOST Perioperative Information Management System (aka PIMS or VPIMS) before 2015R1 has hardcoded credentials, which makes it easier for remote attackers to obtain sensitive information via direct requests to the application database server.
0
Attacker Value
Unknown
CVE-2016-4575
Disclosure Date: May 25, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the email APP in Huawei PLK smartphones with software AL10C00 before AL10C00B211 and AL10C92 before AL10C92B211; ATH smartphones with software AL00C00 before AL00C00B361, CL00C92 before CL00C92B361, TL00HC01 before TL00HC01B361, and UL00C00 before UL00C00B361; CherryPlus smartphones with software TL00C00 before TL00C00B553, UL00C00 before UL00C00B553, and TL00MC01 before TL00MC01B553; and RIO smartphones with software AL00C00 before AL00C00B360 allows remote attackers to inject arbitrary web script or HTML via an email message.
0
Attacker Value
Unknown
CVE-2015-4823
Disclosure Date: October 21, 2015 (last updated October 05, 2023)
Unspecified vulnerability in the Hyperion Installation Technology component in Oracle Hyperion 11.1.2.3 allows local users to affect confidentiality via unknown vectors related to Essbase Rapid Deploy.
0
Attacker Value
Unknown
CVE-2015-4773
Disclosure Date: July 16, 2015 (last updated October 05, 2023)
Unspecified vulnerability in the Hyperion Common Security component in Oracle Hyperion 11.1.2.2, 11.1.2.3, and 11.1.2.4 allows remote authenticated users to affect availability via unknown vectors related to User Account Update.
0
Attacker Value
Unknown
CVE-2015-2584
Disclosure Date: July 16, 2015 (last updated October 05, 2023)
Unspecified vulnerability in the Hyperion Enterprise Performance Management Architect component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect integrity via unknown vectors related to Security, a different vulnerability than CVE-2015-2592.
0
Attacker Value
Unknown
CVE-2015-2592
Disclosure Date: July 16, 2015 (last updated October 05, 2023)
Unspecified vulnerability in the Hyperion Enterprise Performance Management Architect component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect integrity via unknown vectors related to Security, a different vulnerability than CVE-2015-2584.
0