Show filters
602 Total Results
Displaying 471-480 of 602
Sort by:
Attacker Value
Unknown
CVE-2014-100002
Disclosure Date: January 13, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the attach parameter to WorkOrder.do in the file attachment for a new ticket.
0
Attacker Value
Unknown
CVE-2014-7209
Disclosure Date: January 06, 2015 (last updated October 05, 2023)
run-mailcap in the Debian mime-support package before 3.52-1+deb7u1 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename.
0
Attacker Value
Unknown
CVE-2014-9179
Disclosure Date: December 02, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the SupportEzzy Ticket System plugin 1.2.5 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the "URL (optional)" field in a new ticket.
0
Attacker Value
Unknown
CVE-2014-0484
Disclosure Date: September 22, 2014 (last updated October 05, 2023)
The Debian acpi-support package before 0.140-5+deb7u3 allows local users to gain privileges via vectors related to the "user's environment."
0
Attacker Value
Unknown
CVE-2014-5868
Disclosure Date: September 11, 2014 (last updated October 05, 2023)
The Cisco Technical Support (aka com.cisco.swtg_android) application 3.7.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-4199
Disclosure Date: August 28, 2014 (last updated October 05, 2023)
vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, allows local users to write to arbitrary files via a symlink attack on a file in /tmp.
0
Attacker Value
Unknown
CVE-2014-4200
Disclosure Date: August 28, 2014 (last updated October 05, 2023)
vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, uses 0644 permissions for the vm-support archive, which allows local users to obtain sensitive information by extracting files from this archive.
0
Attacker Value
Unknown
CVE-2014-1419
Disclosure Date: July 24, 2014 (last updated October 05, 2023)
Race condition in the power policy functions in policy-funcs in acpi-support before 0.142 allows local users to gain privileges via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-2594
Disclosure Date: January 21, 2014 (last updated October 05, 2023)
SQL injection vulnerability in reports/calldiary.php in Hornbill Supportworks ITSM 1.0.0 through 3.4.14 allows remote attackers to execute arbitrary SQL commands via the callref parameter.
0
Attacker Value
Unknown
CVE-2013-0572
Disclosure Date: April 27, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in IBM Document Connect for Application Support Facility (aka DC4ASF) before 1.0.0.1218 in Application Support Facility (ASF) 3.4 for z/OS on Windows, Linux, and AIX allows remote authenticated users to inject content, and conduct phishing attacks, via unspecified vectors.
0