Show filters
189 Total Results
Displaying 71-80 of 189
Sort by:
Attacker Value
Unknown

CVE-2020-15492

Disclosure Date: July 23, 2020 (last updated February 21, 2025)
An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe web application (served on TCP port 85) includes user input into a filesystem access without any further validation. This might allow an unauthenticated attacker to read files on the server via Directory Traversal, or possibly have unspecified other impact.
Attacker Value
Unknown

CVE-2020-14954

Disclosure Date: June 21, 2020 (last updated February 21, 2025)
Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a man-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection."
Attacker Value
Unknown

CVE-2019-12735

Disclosure Date: June 05, 2019 (last updated November 08, 2023)
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim.
0
Attacker Value
Unknown

CVE-2018-1000820

Disclosure Date: December 20, 2018 (last updated November 27, 2024)
neo4j-contrib neo4j-apoc-procedures version before commit 45bc09c contains a XML External Entity (XXE) vulnerability in XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This vulnerability appears to have been fixed in after commit 45bc09c.
0
Attacker Value
Unknown

CVE-2018-0687

Disclosure Date: November 15, 2018 (last updated November 27, 2024)
Cross-site scripting vulnerability in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2018-0685

Disclosure Date: November 15, 2018 (last updated November 27, 2024)
SQL injection vulnerability in the Denbun POP version V3.3P R4.0 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via HTTP requests for mail search.
0
Attacker Value
Unknown

CVE-2018-0683

Disclosure Date: November 15, 2018 (last updated November 27, 2024)
Buffer overflow in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote attackers to execute arbitrary code or cause a denial-of-service (DoS) condition via Cookie data.
0
Attacker Value
Unknown

CVE-2018-0682

Disclosure Date: November 15, 2018 (last updated November 27, 2024)
Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) does not properly manage sessions, which allows remote attackers to read/send mail or change the configuration via unspecified vectors.
0
Attacker Value
Unknown

CVE-2018-0684

Disclosure Date: November 15, 2018 (last updated November 27, 2024)
Buffer overflow in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R3.0 and earlier, Denbun IMAP version V3.3I R3.0 and earlier) allows remote attackers to execute arbitrary code or cause a denial-of-service (DoS) condition via multipart/form-data format data.
0
Attacker Value
Unknown

CVE-2018-0680

Disclosure Date: November 15, 2018 (last updated November 27, 2024)
Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses hard-coded credentials, which may allow remote attackers to read/send mail or change the configuration.
0