Show filters
80 Total Results
Displaying 61-70 of 80
Sort by:
Attacker Value
Unknown
CVE-2018-18362
Disclosure Date: December 06, 2018 (last updated November 27, 2024)
Norton Password Manager for Android (formerly Norton Identity Safe) may be susceptible to a cross site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to potentially bypass access controls such as the same-origin policy.
0
Attacker Value
Unknown
CVE-2018-12240
Disclosure Date: August 29, 2018 (last updated November 27, 2024)
The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation issue via a hard coded IV, which is a type of vulnerability that can potentially increase the likelihood of encrypted data being recovered without adequate credentials.
0
Attacker Value
Unknown
CVE-2018-6306
Disclosure Date: April 19, 2018 (last updated November 26, 2024)
Unauthorized code execution from specific DLL and is known as DLL Hijacking attack in Kaspersky Password Manager versions before 8.0.6.538.
0
Attacker Value
Unknown
CVE-2017-17698
Disclosure Date: December 15, 2017 (last updated November 26, 2024)
Zoho ManageEngine Password Manager Pro 9 before 9.4 (9400) has reflected XSS in SearchResult.ec and BulkAccessControlView.ec.
0
Attacker Value
Unknown
CVE-2017-8296
Disclosure Date: April 27, 2017 (last updated November 26, 2024)
kedpm 0.5 and 1.0 creates a history file in ~/.kedpm/history that is written in cleartext. All of the commands performed in the password manager are written there. This can lead to the disclosure of the master password if the "password" command is used with an argument. The names of the password entries created and consulted are also accessible in cleartext.
0
Attacker Value
Unknown
CVE-2016-1161
Disclosure Date: April 20, 2017 (last updated November 26, 2024)
Cross-site request forgery (CSRF) vulnerability in ManageEngine Password Manager Pro before 8.5 (Build 8500).
0
Attacker Value
Unknown
CVE-2016-3987
Disclosure Date: April 12, 2016 (last updated November 25, 2024)
The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefaultBrowser or (2) api/showSB.
0
Attacker Value
Unknown
CVE-2015-5459
Disclosure Date: July 08, 2015 (last updated October 05, 2023)
SQL injection vulnerability in the AdvanceSearch.class in AdventNetPassTrix.jar in ManageEngine Password Manager Pro (PMP) before 8.1 Build 8101 allows remote authenticated users to execute arbitrary SQL commands via the ANDOR parameter, as demonstrated by a request to STATE_ID/1425543888647/SQLAdvancedALSearchResult.cc.
0
Attacker Value
Unknown
CVE-2014-9372
Disclosure Date: December 16, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remote attackers to delete arbitrary files via a .. (dot dot) in a filename.
0
Attacker Value
Unknown
CVE-2014-3997
Disclosure Date: December 05, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition 5 through 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to MetadataServlet.dat.
0