Show filters
99 Total Results
Displaying 51-60 of 99
Sort by:
Attacker Value
Unknown
CVE-2014-0243
Disclosure Date: July 19, 2018 (last updated November 08, 2023)
Check_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a file in /var/lib/check_mk_agent/job.
0
Attacker Value
Unknown
EpubCheck 4.0.1 is vulnerable to external XML entity processing attacks
Disclosure Date: July 13, 2018 (last updated November 27, 2024)
EpubCheck 4.0.1 does not properly restrict resolving external entities when parsing XML in EPUB files during validation. An attacker who supplies a specially crafted EPUB file may be able to exploit this behavior to read arbitrary files, or have the victim execute arbitrary requests on his behalf, abusing the victim's trust relationship with other entities.
0
Attacker Value
Unknown
CVE-2018-3759
Disclosure Date: June 13, 2018 (last updated November 26, 2024)
private_address_check ruby gem before 0.5.0 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition due to the address the socket uses not being checked. DNS entries with a TTL of 0 can trigger this case where the initial resolution is a public address but the subsequent resolution is a private address.
0
Attacker Value
Unknown
CVE-2018-12036
Disclosure Date: June 07, 2018 (last updated November 26, 2024)
OWASP Dependency-Check before 3.2.0 allows attackers to write to arbitrary files via a crafted archive that holds directory traversal filenames.
0
Attacker Value
Unknown
CVE-2017-11507
Disclosure Date: December 11, 2017 (last updated November 26, 2024)
A cross site scripting (XSS) vulnerability exists in Check_MK versions 1.2.8x prior to 1.2.8p25 and 1.4.0x prior to 1.4.0p9, allowing an unauthenticated attacker to inject arbitrary HTML or JavaScript via the output_format parameter, and the username parameter of failed HTTP basic authentication attempts, which is returned unencoded in an internal server error page.
0
Attacker Value
Unknown
CVE-2017-0909
Disclosure Date: November 16, 2017 (last updated November 26, 2024)
The private_address_check ruby gem before 0.4.1 is vulnerable to a bypass due to an incomplete blacklist of common private/local network addresses used to prevent server-side request forgery.
0
Attacker Value
Unknown
CVE-2017-0904
Disclosure Date: November 13, 2017 (last updated November 26, 2024)
The private_address_check ruby gem before 0.4.0 is vulnerable to a bypass due to use of Ruby's Resolv.getaddresses method, which is OS-dependent and should not be relied upon for security measures, such as when used to blacklist private network addresses to prevent server-side request forgery.
0
Attacker Value
Unknown
CVE-2017-1000109
Disclosure Date: October 05, 2017 (last updated November 26, 2024)
The custom Details view of the Static Analysis Utilities based OWASP Dependency-Check Plugin, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to this plugin could insert arbitrary HTML into this view.
0
Attacker Value
Unknown
CVE-2017-2188
Disclosure Date: July 07, 2017 (last updated November 26, 2024)
Untrusted search path vulnerability in Installer of Denshinouhin Check System (for Ministry of Agriculture, Forestry and Fisheries Nouson Seibi Jigyou) 2014 March Edition (Ver.9.0.001.001) [Updated on 2017 June 9], (Ver.8.0.001.001) [Updated on 2016 May 31] and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
0
Attacker Value
Unknown
CVE-2017-2230
Disclosure Date: July 07, 2017 (last updated November 26, 2024)
Untrusted search path vulnerability in Douro Kouji Kanseizutou Check Program Ver3.1 (cdrw_checker_3.1.0.lzh) and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
0