Show filters
2,806 Total Results
Displaying 1-10 of 2,806
Sort by:
Attacker Value
Moderate

CVE-2021-3438

Disclosure Date: May 20, 2021 (last updated November 28, 2024)
A potential buffer overflow in the software drivers for certain HP LaserJet products and Samsung product printers could lead to an escalation of privilege.
Attacker Value
Moderate

CVE-2020-25538

Disclosure Date: November 13, 2020 (last updated November 28, 2024)
An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in the web page. In this way, attacker can takeover the control of the server.
Attacker Value
Moderate

CVE-2020-25557

Disclosure Date: November 13, 2020 (last updated November 28, 2024)
In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when attacker logs in to the application, attacker's code will be run. As a result of this vulnerability, authenticated user can run command on the server.
Attacker Value
Unknown

CVE-2016-1010

Disclosure Date: March 12, 2016 (last updated November 25, 2024)
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0963 and CVE-2016-0993.
Attacker Value
Unknown

CVE-2009-3869

Disclosure Date: November 05, 2009 (last updated October 04, 2023)
Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a crafted argument, aka Bug Id 6872357.
1
Attacker Value
High

CVE-2007-2617

Disclosure Date: May 11, 2007 (last updated October 04, 2023)
srsexec in Sun Remote Services (SRS) Net Connect Software Proxy Core package in Sun Solaris 10 does not enforce file permissions when opening files, which allows local users to read the first line of arbitrary files via the -d and -v options.
0
Attacker Value
Unknown

CVE-2025-20907

Disclosure Date: February 04, 2025 (last updated February 13, 2025)
Improper privilege management in Samsung Find prior to SMR Feb-2025 Release 1 allows local privileged attackers to disable Samsung Find.
Attacker Value
Unknown

CVE-2025-20906

Disclosure Date: February 04, 2025 (last updated February 04, 2025)
Improper Export of Android Application Components in Settings prior to SMR Feb-2025 Release 1 allows local attackers to enable ADB.
0
Attacker Value
Unknown

CVE-2025-20905

Disclosure Date: February 04, 2025 (last updated February 13, 2025)
Out-of-bounds read and write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to read and write out-of-bounds memory.
Attacker Value
Unknown

CVE-2025-20904

Disclosure Date: February 04, 2025 (last updated February 13, 2025)
Out-of-bounds write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to cause memory corruption.