Show filters
87 Total Results
Displaying 71-80 of 87
Sort by:
Attacker Value
Unknown
CVE-2016-1202
Disclosure Date: April 25, 2016 (last updated November 25, 2024)
Untrusted search path vulnerability in Atom Electron before 0.33.5 allows local users to gain privileges via a Trojan horse Node.js module in a parent directory of a directory named on a require line.
0
Attacker Value
Unknown
CVE-2014-7457
Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Electronics For You (aka com.magzter.electronicsforyou) application 3.02 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2011-3700
Disclosure Date: September 23, 2011 (last updated October 04, 2023)
Advanced Electron Forum (AEF) 1.0.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by languages/english/deletetopic_lang.php.
0
Attacker Value
Unknown
CVE-2009-4776
Disclosure Date: April 21, 2010 (last updated October 04, 2023)
Buffer overflow in Hitachi Cosminexus V4 through V8, Processing Kit for XML, and Developer's Kit for Java, as used in products such as uCosminexus, Electronic Form Workflow, Groupmax, and IBM XL C/C++ Enterprise Edition 7 and 8, allows remote attackers to have an unknown impact via vectors related to the use of GIF image processing APIs by a Java application, and a different issue from CVE-2007-3794.
0
Attacker Value
Unknown
CVE-2009-2545
Disclosure Date: July 20, 2009 (last updated October 04, 2023)
SQL injection vulnerability in Advanced Electron Forum (AEF) 1.x, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the filename in an uploaded attachment. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2009-2546
Disclosure Date: July 20, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in Advanced Electron Forum (AEF) 1.x allows remote attackers to determine the existence of arbitrary files via the avatargalfile parameter when changing an avatar, which leaks the existence of the file in an error message. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2008-5383
Disclosure Date: December 09, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in National Instruments Electronics Workbench allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted .ewb file.
0
Attacker Value
Unknown
CVE-2008-5090
Disclosure Date: November 14, 2008 (last updated October 04, 2023)
Electron Inc. Advanced Electron Forum before 1.0.7 allows remote attackers to execute arbitrary PHP code via PHP code embedded in bbcode in the email parameter, which is processed by the preg_replace function with the eval switch.
0
Attacker Value
Unknown
CVE-2008-1983
Disclosure Date: April 27, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Advanced Electron Forum (AEF) 1.0.6 allows remote attackers to inject arbitrary web script or HTML via the beg parameter in a members action to index.php.
0
Attacker Value
Unknown
CVE-2007-4563
Disclosure Date: August 28, 2007 (last updated October 04, 2023)
Cosminexus Manager in Cosminexus Application Server 06-50 and later might assign the wrong user's group permissions to logical J2EE server processes, which allows local users to gain privileges.
0