Show filters
185 Total Results
Displaying 1-10 of 185
Sort by:
Attacker Value
Very High
CVE-2014-6271
Disclosure Date: September 24, 2014 (last updated July 25, 2024)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
2
Attacker Value
Unknown
CVE-2024-40706
Disclosure Date: January 24, 2025 (last updated January 25, 2025)
IBM InfoSphere Information Server 11.7 could allow a remote user to obtain sensitive version information that could aid in further attacks against the system.
0
Attacker Value
Unknown
CVE-2024-52363
Disclosure Date: January 17, 2025 (last updated January 17, 2025)
IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
0
Attacker Value
Unknown
CVE-2021-29827
Disclosure Date: December 19, 2024 (last updated December 19, 2024)
IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.
0
Attacker Value
Unknown
CVE-2024-52901
Disclosure Date: December 12, 2024 (last updated January 13, 2025)
IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to improper input validation.
0
Attacker Value
Unknown
CVE-2024-51460
Disclosure Date: December 11, 2024 (last updated January 15, 2025)
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system.
0
Attacker Value
Unknown
CVE-2023-23472
Disclosure Date: December 11, 2024 (last updated December 21, 2024)
IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system.
0
Attacker Value
Unknown
CVE-2024-40705
Disclosure Date: August 15, 2024 (last updated August 16, 2024)
IBM InfoSphere Information Server could allow an authenticated user to consume file space resources due to unrestricted file uploads. IBM X-Force ID: 298279.
0
Attacker Value
Unknown
CVE-2024-40704
Disclosure Date: August 15, 2024 (last updated August 16, 2024)
IBM InfoSphere Information Server 11.7 could allow a privileged user to obtain sensitive information from authentication request headers. IBM X-Force ID: 298277.
0
Attacker Value
Unknown
CVE-2024-39751
Disclosure Date: August 06, 2024 (last updated August 30, 2024)
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 297429
0