Show filters
602 Total Results
Displaying 461-470 of 602
Sort by:
Attacker Value
Unknown
CVE-2017-3371
Disclosure Date: January 27, 2017 (last updated November 25, 2024)
Vulnerability in the Oracle iSupport component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iSupport, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iSupport accessible data as well as unauthorized update, insert or delete access to some of Oracle iSupport accessible data. CVSS v3.0 Base Score 8.2 (Confidentiality and Integrity impacts).
0
Attacker Value
Unknown
CVE-2017-3369
Disclosure Date: January 27, 2017 (last updated November 25, 2024)
Vulnerability in the Oracle iSupport component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iSupport, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iSupport accessible data as well as unauthorized update, insert or delete access to some of Oracle iSupport accessible data. CVSS v3.0 Base Score 8.2 (Confidentiality and Integrity impacts).
0
Attacker Value
Unknown
CVE-2016-3949
Disclosure Date: June 27, 2016 (last updated November 25, 2024)
Siemens SIMATIC S7-300 Profinet-enabled CPU devices with firmware before 3.2.12 and SIMATIC S7-300 Profinet-disabled CPU devices with firmware before 3.3.12 allow remote attackers to cause a denial of service (defect-mode transition) via crafted (1) ISO-TSAP or (2) Profibus packets.
0
Attacker Value
Unknown
CVE-2016-2245
Disclosure Date: March 19, 2016 (last updated November 25, 2024)
HP Support Assistant before 8.1.52.1 allows remote attackers to bypass authentication via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-3197
Disclosure Date: February 15, 2016 (last updated November 08, 2023)
ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by performing computations on SSLv2 traffic, related to the get_client_master_key and get_client_hello functions.
0
Attacker Value
Unknown
CVE-2015-5149
Disclosure Date: June 30, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in Zoho ManageEngine SupportCenter Plus 7.90 allows remote authenticated users to write to arbitrary files via a .. (dot dot) in the component parameter in the Request component to workorder/Attachment.jsp.
0
Attacker Value
Unknown
CVE-2015-5150
Disclosure Date: June 30, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Zoho ManageEngine SupportCenter Plus 7.90 allow remote authenticated users to inject arbitrary web script or HTML via the (1) query parameter in the run_query_editor_query module to CustomReportHandler.do, (2) compAcct parameter to jsp/ResetADPwd.jsp, or (3) redirectTo parameter to jsp/CacheScreenWidth.jsp.
0
Attacker Value
Unknown
CVE-2015-0935
Disclosure Date: May 25, 2015 (last updated October 05, 2023)
Bomgar Remote Support before 15.1.1 allows remote attackers to execute arbitrary PHP code via crafted serialized data to unspecified PHP scripts.
0
Attacker Value
Unknown
CVE-2015-2114
Disclosure Date: April 14, 2015 (last updated October 05, 2023)
HP Support Solution Framework before 11.51.0049 allows remote attackers to download an arbitrary program onto a client machine and execute this program via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-0866
Disclosure Date: February 02, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Zoho ManageEngine SupportCenter Plus 7.9 before hotfix 7941 allow remote attackers to inject arbitrary web script or HTML via the (1) fromCustomer, (2) username, or (3) password parameter to HomePage.do.
0