Show filters
150 Total Results
Displaying 71-80 of 150
Sort by:
Attacker Value
Unknown

CVE-2015-5312

Disclosure Date: December 15, 2015 (last updated October 05, 2023)
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.
0
Attacker Value
Unknown

CVE-2015-8241

Disclosure Date: December 15, 2015 (last updated October 05, 2023)
The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
0
Attacker Value
Unknown

CVE-2015-8242

Disclosure Date: December 15, 2015 (last updated October 05, 2023)
The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
0
Attacker Value
Unknown

CVE-2015-8317

Disclosure Date: December 15, 2015 (last updated October 05, 2023)
The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.
0
Attacker Value
Unknown

CVE-2015-5444

Disclosure Date: October 18, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in HP Smart Profile Server Data Analytics Layer (SPS DAL) 2.3 before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-5711

Disclosure Date: September 29, 2015 (last updated October 05, 2023)
TIBCO Managed File Transfer Internet Server before 7.2.5, Managed File Transfer Command Center before 7.2.5, Slingshot before 1.9.4, and Vault before 2.0.1 allow remote authenticated users to obtain sensitive information via a crafted HTTP request.
0
Attacker Value
Unknown

CVE-2014-9439

Disclosure Date: January 02, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Easy File Sharing Web Server 6.8 allows remote attackers to inject arbitrary web script or HTML via the username field during registration, which is not properly handled by forum.ghp.
0
Attacker Value
Unknown

CVE-2014-7194

Disclosure Date: November 21, 2014 (last updated October 05, 2023)
TIBCO Managed File Transfer Internet Server before 7.2.4, Managed File Transfer Command Center before 7.2.4, Slingshot before 1.9.3, and Vault before 1.1.1 allow remote attackers to obtain sensitive information or modify data by leveraging agent access.
0
Attacker Value
Unknown

CVE-2014-7226

Disclosure Date: October 10, 2014 (last updated October 05, 2023)
The file comment feature in Rejetto HTTP File Server (hfs) 2.3c and earlier allows remote attackers to execute arbitrary code by uploading a file with certain invalid UTF-8 byte sequences that are interpreted as executable macro symbols.
0
Attacker Value
Unknown

CVE-2014-6287

Disclosure Date: October 07, 2014 (last updated November 25, 2024)
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.