Show filters
144 Total Results
Displaying 71-80 of 144
Sort by:
Attacker Value
Unknown

CVE-2013-6876

Disclosure Date: April 06, 2018 (last updated November 26, 2024)
The (1) pty_init_terminal and (2) pipe_init_terminal functions in main.c in s3dvt 0.2.2 and earlier allows local users to gain privileges by leveraging setuid permissions and usage of bash 4.3 and earlier. NOTE: this vulnerability was fixed with commit ad732f00b411b092c66a04c359da0f16ec3b387, but the version number was not changed.
0
Attacker Value
Unknown

CVE-2018-8754

Disclosure Date: March 18, 2018 (last updated November 08, 2023)
The libevt_record_values_read_event() function in libevt_record_values.c in libevt before 2018-03-17 does not properly check for out-of-bounds values of user SID data size, strings size, or data size. NOTE: the vendor has disputed this as described in libyal/libevt issue 5 on GitHub
Attacker Value
Unknown

CVE-2018-7472

Disclosure Date: February 25, 2018 (last updated November 26, 2024)
INVT Studio 1.2 allows remote attackers to cause a denial of service during import operations.
0
Attacker Value
Unknown

CVE-2017-7483

Disclosure Date: May 02, 2017 (last updated November 26, 2024)
Rxvt 2.7.10 is vulnerable to a denial of service attack by passing the value -2^31 inside a terminal escape code, which results in a non-invertible integer that eventually leads to a segfault due to an out of bounds read.
Attacker Value
Unknown

CVE-2016-1713

Disclosure Date: April 14, 2017 (last updated November 26, 2024)
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.4.0 allows remote authenticated users to execute arbitrary code by uploading a crafted image file with an executable extension, then accessing it via a direct request to the file in test/logo/. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-6000.
0
Attacker Value
Unknown

CVE-2016-4834

Disclosure Date: August 01, 2016 (last updated November 25, 2024)
modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allows remote authenticated users to create or modify user accounts via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-7392

Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Russian Federation Traffic Rules (aka com.russia.pdd) application 1.21 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-6816

Disclosure Date: September 30, 2014 (last updated October 05, 2023)
The WISDOM (aka lvtu99.com.nescmxiaoniuniu) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-1222

Disclosure Date: August 12, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in kcfinder/browse.php in Vtiger CRM before 6.0.0 Security patch 1 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file parameter in a download action. NOTE: it is likely that this issue is actually in the KCFinder third-party component, and it affects additional products besides Vtiger CRM.
0
Attacker Value
Unknown

CVE-2014-2268

Disclosure Date: April 22, 2014 (last updated October 05, 2023)
views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which allows remote attackers to re-install the application via a request that sets the X-Requested-With HTTP header, as demonstrated by executing arbitrary PHP code via the db_name parameter.
0