Show filters
84 Total Results
Displaying 1-10 of 84
Sort by:
Attacker Value
Unknown
CVE-2017-6369
Disclosure Date: March 24, 2017 (last updated November 26, 2024)
Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticated users to execute code by using a 'system' entrypoint from fbudf.so.
1
Attacker Value
Moderate
CVE-2013-2492
Disclosure Date: March 15, 2013 (last updated October 05, 2023)
Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute arbitrary code via a crafted packet to TCP port 3050, related to a missing size check during extraction of a group number from CNCT information.
0
Attacker Value
Unknown
CVE-2024-51377
Disclosure Date: November 01, 2024 (last updated November 15, 2024)
An issue in Ladybird Web Solution Faveo Helpdesk & Servicedesk (On-Premise and Cloud) 9.2.0 allows a remote attacker to execute arbitrary code via the Subject and Identifier fields
0
Attacker Value
Unknown
CVE-2024-7209
Disclosure Date: July 30, 2024 (last updated July 31, 2024)
A vulnerability exists in the use of shared SPF records in multi-tenant hosting providers, allowing attackers to use network authorization to be abused to spoof the email identify of the sender.
0
Attacker Value
Unknown
CVE-2023-41038
Disclosure Date: March 20, 2024 (last updated April 02, 2024)
Firebird is a relational database. Versions 4.0.0 through 4.0.3 and version 5.0 beta1 are vulnerable to a server crash when a user uses a specific form of SET BIND statement. Any non-privileged user with minimum access to a server may type a statement with a long `CHAR` length, which causes the server to crash due to stack corruption. Versions 4.0.4.2981 and 5.0.0.117 contain fixes for this issue. No known workarounds are available.
0
Attacker Value
Unknown
CVE-2023-1724
Disclosure Date: June 24, 2023 (last updated October 08, 2023)
Faveo Helpdesk Enterprise version 6.0.1 allows an attacker with agent permissions to perform privilege escalation on the application. This occurs because the application is vulnerable to stored XSS.
0
Attacker Value
Unknown
CVE-2023-2505
Disclosure Date: May 22, 2023 (last updated October 08, 2023)
The affected products have a CSRF vulnerability that could allow an attacker to execute code and upload malicious files.
0
Attacker Value
Unknown
CVE-2023-2504
Disclosure Date: May 22, 2023 (last updated October 08, 2023)
Files present on firmware images could allow an attacker to gain unauthorized access as a root user using hard-coded credentials.
0
Attacker Value
Unknown
CVE-2023-23654
Disclosure Date: May 15, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SparkPost plugin <= 3.2.5 versions.
0
Attacker Value
Unknown
CVE-2023-0542
Disclosure Date: May 08, 2023 (last updated October 08, 2023)
The Custom Post Type List Shortcode WordPress plugin through 1.4.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
0