Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2024-51723

Disclosure Date: November 25, 2024 (last updated January 05, 2025)
A Stored Cross-Site Scripting (XSS) vulnerability in the Management Console of BlackBerry AtHoc version 7.15 could allow an attacker to potentially execute actions in the context of the victim's session.
0
Attacker Value
Unknown

CVE-2023-21523

Disclosure Date: September 12, 2023 (last updated October 08, 2023)
A Stored Cross-site Scripting (XSS) vulnerability in the Management Console (User Management and Alerts) of BlackBerry AtHoc version 7.15 could allow an attacker to execute script commands in the context of the affected user account.
Attacker Value
Unknown

CVE-2023-21520

Disclosure Date: September 12, 2023 (last updated October 08, 2023)
A PII Enumeration via Credential Recovery in the Self Service (Credential Recovery) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially associate a list of contact details with an AtHoc IWS organization.
Attacker Value
Unknown

CVE-2023-21522

Disclosure Date: September 12, 2023 (last updated October 08, 2023)
A Reflected Cross-site Scripting (XSS) vulnerability in the Management Console (Reports) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially control a script that is executed in the victim's browser then they can execute script commands in the context of the affected user account. 
Attacker Value
Unknown

CVE-2023-21521

Disclosure Date: September 12, 2023 (last updated November 08, 2023)
An SQL Injection vulnerability in the Management Console  (Operator Audit Trail) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database, recover the content of a given file present on the DBMS file system and in some cases issue commands to the operating system.
Attacker Value
Unknown

CVE-2019-8997

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions earlier than 7.6 HF-567 could allow an attacker to potentially read arbitrary local files from the application server or make requests on the network by entering maliciously crafted XML in an existing field.
0
Attacker Value
Unknown

CVE-2005-0187

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Stack-based buffer overflow in the SetSkin function in AtHoc toolbar allows remote attackers to execute arbitrary code via a long skin name.
0
Attacker Value
Unknown

CVE-2005-0188

Disclosure Date: October 06, 2004 (last updated February 22, 2025)
Format string vulnerability in the SetBaseURL function in AtHoc toolbar allows remote attackers to execute arbitrary code via format string specifiers in an invalid URL that is recorded in the debug log.
0