Show filters
89 Total Results
Displaying 51-60 of 89
Sort by:
Attacker Value
Unknown

CVE-2016-1000107

Disclosure Date: December 10, 2019 (last updated November 27, 2024)
inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.
Attacker Value
Unknown

CVE-2019-12887

Disclosure Date: June 27, 2019 (last updated November 27, 2024)
KeyIdentity LinOTP before 2.10.5.3 has Incorrect Access Control (issue 1 of 2).
0
Attacker Value
Unknown

CVE-2018-16797

Disclosure Date: September 10, 2018 (last updated November 27, 2024)
A heap-based buffer overflow in PotPlayerMini.exe in PotPlayer 1.7.8556 allows remote attackers to execute arbitrary code via a .wav file with large BytesPerSec and SamplesPerSec values, and a small Data_Chunk_Size value.
0
Attacker Value
Unknown

CVE-2018-14878

Disclosure Date: August 13, 2018 (last updated November 27, 2024)
JetBrains dotPeek before 2018.2 and ReSharper Ultimate before 2018.1.4 allow attackers to execute code by decompiling a compiled .NET object (such as a DLL or EXE file) with a specific file, because of Deserialization of Untrusted Data.
0
Attacker Value
Unknown

CVE-2018-6644

Disclosure Date: February 08, 2018 (last updated November 26, 2024)
SBLIM Small Footprint CIM Broker (SFCB) 1.4.9 has a null pointer (DoS) vulnerability via a crafted POST request to the /cimom URI.
0
Attacker Value
Unknown

CVE-2017-1000385

Disclosure Date: December 12, 2017 (last updated November 26, 2024)
The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server's private key (this is a variation of the Bleichenbacher attack).
0
Attacker Value
Unknown

CVE-2014-9514

Disclosure Date: August 28, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in BMC Footprints Service Core 11.5.
0
Attacker Value
Unknown

CVE-2016-10253

Disclosure Date: March 18, 2017 (last updated November 26, 2024)
An issue was discovered in Erlang/OTP 18.x. Erlang's generation of compiled regular expressions is vulnerable to a heap overflow. Regular expressions using a malformed extpattern can indirectly specify an offset that is used as an array index. This ordinal permits arbitrary regions within the erts_alloc arena to be both read and written to.
0
Attacker Value
Unknown

CVE-2016-1000217

Disclosure Date: October 06, 2016 (last updated November 25, 2024)
Zotpress plugin for WordPress SQLi in zp_get_account()
0
Attacker Value
Unknown

CVE-2015-2774

Disclosure Date: April 07, 2016 (last updated November 25, 2024)
Erlang/OTP before 18.0-rc1 does not properly check CBC padding bytes when terminating connections, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).
0