Show filters
200 Total Results
Displaying 91-100 of 200
Sort by:
Attacker Value
Unknown

CVE-2018-16638

Disclosure Date: December 28, 2018 (last updated November 27, 2024)
Evolution CMS 1.4.x allows XSS via the manager/ search parameter.
0
Attacker Value
Unknown

CVE-2018-1000889

Disclosure Date: December 28, 2018 (last updated November 27, 2024)
Logisim Evolution version 2.14.3 and earlier contains an XML External Entity (XXE) vulnerability in Circuit file loading functionality (loadXmlFrom in src/com/cburch/logisim/file/XmlReader.java) that can result in information leak, possible RCE depending on system configuration. This attack appears to be exploitable via the victim opening a specially crafted circuit file. This vulnerability appears to have been fixed in 2.14.4.
0
Attacker Value
Unknown

CVE-2018-17556

Disclosure Date: September 26, 2018 (last updated November 27, 2024)
MODX Revolution v2.6.5-pl allows stored XSS via a Create New Media Source action.
0
Attacker Value
Unknown

CVE-2016-10727

Disclosure Date: July 20, 2018 (last updated November 27, 2024)
camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. The server code was intended to report an error and not proceed, but the code was written incorrectly.
0
Attacker Value
Unknown

CVE-2018-1000207

Disclosure Date: July 13, 2018 (last updated November 27, 2024)
MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpthumb class that can result in Creating file with custom a filename and content. This attack appear to be exploitable via Web request. This vulnerability appears to have been fixed in commit 06bc94257408f6a575de20ddb955aca505ef6e68.
0
Attacker Value
Unknown

CVE-2018-1000208

Disclosure Date: July 13, 2018 (last updated November 27, 2024)
MODX Revolution version <=2.6.4 contains a Directory Traversal vulnerability in /core/model/modx/modmanagerrequest.class.php that can result in remove files. This attack appear to be exploitable via web request via security/login processor. This vulnerability appears to have been fixed in pull 13980.
0
Attacker Value
Unknown

CVE-2018-1000540

Disclosure Date: June 26, 2018 (last updated November 26, 2024)
LoboEvolution version < 9b75694cedfa4825d4a2330abf2719d470c654cd contains a XML External Entity (XXE) vulnerability in XML Parsing when viewing the XML file in the browser that can result in disclosure of confidential data, denial of service, server side request forgery. This attack appear to be exploitable via Specially crafted XML file.
0
Attacker Value
Unknown

CVE-2018-12422

Disclosure Date: June 15, 2018 (last updated November 08, 2023)
addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger a Buffer Overflow via a long query that is processed by the strcat function. NOTE: the software maintainer disputes this because "the code had computed the required string length first, and then allocated a large-enough buffer on the heap.
0
Attacker Value
Unknown

CVE-2018-10382

Disclosure Date: June 01, 2018 (last updated November 26, 2024)
MODX Revolution 2.6.3 has XSS.
0
Attacker Value
Unknown

CVE-2017-17689

Disclosure Date: May 16, 2018 (last updated November 26, 2024)
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
0