Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Low

CVE-2018-14581

Disclosure Date: July 31, 2018 (last updated November 27, 2024)
Redgate .NET Reflector before 10.0.7.774 and SmartAssembly before 6.12.5 allow attackers to execute code by decompiling a compiled .NET object (such as a DLL or EXE file) with a specific embedded resource file.
0
Attacker Value
Unknown

CVE-2023-43896

Disclosure Date: October 10, 2023 (last updated October 18, 2023)
A buffer overflow in Macrium Reflect 8.1.7544 and below allows attackers to escalate privileges or execute arbitrary code.
Attacker Value
Unknown

CVE-2022-39272

Disclosure Date: October 22, 2022 (last updated February 24, 2025)
Flux is an open and extensible continuous delivery solution for Kubernetes. Versions prior to 0.35.0 are subject to a Denial of Service. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields `.spec.interval` or `.spec.timeout` (and structured variations of these fields), causing the entire object type to stop being processed. This issue is patched in version 0.35.0. As a workaround, Admission controllers can be employed to restrict the values that can be used for fields `.spec.interval` and `.spec.timeout`, however upgrading to the latest versions is still the recommended mitigation.
Attacker Value
Unknown

CVE-2021-37468

Disclosure Date: July 25, 2021 (last updated February 23, 2025)
NCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration files.
Attacker Value
Unknown

CVE-2020-10143

Disclosure Date: December 09, 2020 (last updated February 22, 2025)
Macrium Reflect includes an OpenSSL component that specifies an OPENSSLDIR variable as C:\openssl\. Macrium Reflect contains a privileged service that uses this OpenSSL component. Because unprivileged Windows users can create subdirectories off of the system root, a user can create the appropriate path to a specially-crafted openssl.cnf file to achieve arbitrary code execution with SYSTEM privileges.
Attacker Value
Unknown

CVE-2016-5765

Disclosure Date: November 29, 2016 (last updated November 08, 2023)
Administrative Server in Micro Focus Host Access Management and Security Server (MSS) and Reflection for the Web (RWeb) and Reflection Security Gateway (RSG) and Reflection ZFE (ZFE) allows remote unauthenticated attackers to read arbitrary files via a specially crafted URL that allows limited directory traversal. Applies to MSS 12.3 before 12.3.326 and MSS 12.2 before 12.2.342 and RSG 12.1 before 12.1.362 and RWeb 12.3 before 12.3.312 and RWeb 12.2 before 12.2.342 and RWeb 12.1 before 12.1.362 and ZFE 2.0.1 before 2.0.1.18 and ZFE 2.0.0 before 2.0.0.52 and ZFE 1.4.0 before 1.4.0.14.
0
Attacker Value
Unknown

CVE-2014-0603

Disclosure Date: February 06, 2015 (last updated October 05, 2023)
The rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to cause a denial of service (memory corruption) and execute arbitrary code via vectors related to the (1) GetGlobalSettings or (2) GetSiteProperties3 methods, which triggers a dereference of an arbitrary memory address. NOTE: this issue was MERGED with CVE-2014-0606 because it is the same type of vulnerability, affecting the same set of versions, and discovered by the same researcher.
0
Attacker Value
Unknown

CVE-2014-0604

Disclosure Date: February 06, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to execute arbitrary code via unspecified vectors to the StartLog method.
0
Attacker Value
Unknown

CVE-2014-0605

Disclosure Date: February 06, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to execute arbitrary code via unspecified vectors to the SaveSettings method.
0
Attacker Value
Unknown

CVE-2014-5211

Disclosure Date: January 27, 2015 (last updated October 05, 2023)
Stack-based buffer overflow in the Attachmate Reflection FTP Client before 14.1.433 allows remote FTP servers to execute arbitrary code via a large PWD response.
0