Show filters
15 Total Results
Displaying 1-10 of 15
Sort by:
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Attacker Value
Unknown

CVE-2018-6289

Disclosure Date: February 06, 2018 (last updated November 26, 2024)
Configuration file injection leading to Code Execution as Root in Kaspersky Secure Mail Gateway version 1.1.
0
Attacker Value
Unknown

CVE-2018-6290

Disclosure Date: February 06, 2018 (last updated November 26, 2024)
Local Privilege Escalation in Kaspersky Secure Mail Gateway version 1.1.
0
Attacker Value
Unknown

CVE-2018-6291

Disclosure Date: February 06, 2018 (last updated November 26, 2024)
WebConsole Cross-Site Scripting in Kaspersky Secure Mail Gateway version 1.1.
0
Attacker Value
Unknown

CVE-2018-6288

Disclosure Date: February 06, 2018 (last updated November 26, 2024)
Cross-site Request Forgery leading to Administrative account takeover in Kaspersky Secure Mail Gateway version 1.1.
0
Attacker Value
Unknown

CVE-2013-6037

Disclosure Date: March 11, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Aker Secure Mail Gateway 2.5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg_id parameter.
0
Attacker Value
Unknown

CVE-2010-2116

Disclosure Date: May 28, 2010 (last updated October 04, 2023)
The web interface in McAfee Email Gateway (formerly IronMail) 6.7.1 allows remote authenticated users, with only Read privileges, to gain Write privileges to modify configuration via the save action in a direct request to admin/systemWebAdminConfig.do.
0
Attacker Value
Unknown

CVE-2005-0356

Disclosure Date: May 31, 2005 (last updated February 22, 2025)
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.
0
Attacker Value
Unknown

CVE-2004-0937

Disclosure Date: February 09, 2005 (last updated February 22, 2025)
Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
0
Attacker Value
Unknown

CVE-2004-0934

Disclosure Date: January 27, 2005 (last updated February 22, 2025)
Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
0