Show filters
80 Total Results
Displaying 61-70 of 80
Sort by:
Attacker Value
Unknown

CVE-2018-18362

Disclosure Date: December 06, 2018 (last updated November 27, 2024)
Norton Password Manager for Android (formerly Norton Identity Safe) may be susceptible to a cross site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to potentially bypass access controls such as the same-origin policy.
0
Attacker Value
Unknown

CVE-2018-12240

Disclosure Date: August 29, 2018 (last updated November 27, 2024)
The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation issue via a hard coded IV, which is a type of vulnerability that can potentially increase the likelihood of encrypted data being recovered without adequate credentials.
Attacker Value
Unknown

CVE-2018-6306

Disclosure Date: April 19, 2018 (last updated November 26, 2024)
Unauthorized code execution from specific DLL and is known as DLL Hijacking attack in Kaspersky Password Manager versions before 8.0.6.538.
0
Attacker Value
Unknown

CVE-2017-17698

Disclosure Date: December 15, 2017 (last updated November 26, 2024)
Zoho ManageEngine Password Manager Pro 9 before 9.4 (9400) has reflected XSS in SearchResult.ec and BulkAccessControlView.ec.
0
Attacker Value
Unknown

CVE-2017-8296

Disclosure Date: April 27, 2017 (last updated November 26, 2024)
kedpm 0.5 and 1.0 creates a history file in ~/.kedpm/history that is written in cleartext. All of the commands performed in the password manager are written there. This can lead to the disclosure of the master password if the "password" command is used with an argument. The names of the password entries created and consulted are also accessible in cleartext.
0
Attacker Value
Unknown

CVE-2016-1161

Disclosure Date: April 20, 2017 (last updated November 26, 2024)
Cross-site request forgery (CSRF) vulnerability in ManageEngine Password Manager Pro before 8.5 (Build 8500).
0
Attacker Value
Unknown

CVE-2016-3987

Disclosure Date: April 12, 2016 (last updated November 25, 2024)
The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefaultBrowser or (2) api/showSB.
Attacker Value
Unknown

CVE-2015-5459

Disclosure Date: July 08, 2015 (last updated October 05, 2023)
SQL injection vulnerability in the AdvanceSearch.class in AdventNetPassTrix.jar in ManageEngine Password Manager Pro (PMP) before 8.1 Build 8101 allows remote authenticated users to execute arbitrary SQL commands via the ANDOR parameter, as demonstrated by a request to STATE_ID/1425543888647/SQLAdvancedALSearchResult.cc.
0
Attacker Value
Unknown

CVE-2014-9372

Disclosure Date: December 16, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remote attackers to delete arbitrary files via a .. (dot dot) in a filename.
0
Attacker Value
Unknown

CVE-2014-3997

Disclosure Date: December 05, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition 5 through 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to MetadataServlet.dat.
0