Unknown · CVSS Not scored
The Linux kernel before 4.4.1 allows local users to bypass file-descriptor limits and cause a denial of service (memory consumption) by sending each descriptor over a UNIX socket before closing it, related to net/unix/af_unix.c and net/unix/garbage.c.
Published Feb 8, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 processes chunked transfer coding without properly handling (1) a large total amount of chunked data or (2) whitespace characters in an HTTP header value within a trailer field, which allows remote attackers to cause a denial of service by streaming data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3544.
Published Feb 26, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or AJP connector is used, does not properly handle certain inconsistent HTTP request headers, which allows remote attackers to trigger incorrect identification of a request's length and conduct request-smuggling attacks via (1) multiple Content-Length headers or (2) a Content-Length header and a "Transfer-Encoding: chunked" header. NOTE: this vulnerability exists because of an incomplete fix for CVE-2005-2090.
Published Feb 26, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Ajaxeplorer before 5.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) archive_name parameter to the Power FS module (plugins/action.powerfs/class.PowerFSController.php), a (2) file name to the getTrustSizeOnFileSystem function in the File System (Standard) module (plugins/access.fs/class.fsAccessWrapper.php), or the (3) revision parameter to the Subversion Repository module (plugins/meta.svn/class.SvnManager.php).
Published Feb 11, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Authenticated User Page Caching (Authcache) module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to cached pages, which allows remote attackers with the same role-combination as the superuser to obtain sensitive information via the cached pages of the superuser.
Published Feb 18, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, which could let a remote malicious user execute arbitrary PHP code
Published Feb 14, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The OG access fields (visibility fields) implementation in Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to private groups, which allows remote authenticated users to guess node IDs, subscribe to, and read the content of arbitrary private groups via unspecified vectors.
Published Feb 18, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in persona.module in the Mozilla Persona module 7.x-1.x before 7.x-1.11 for Drupal allows remote attackers to hijack the authentication of aribitrary users via a security token that is not a string data type.
Published Feb 18, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it easier for remote authenticated users with the "access resource node" and "create page content" permissions (or equivalents) to conduct cross-site scripting (XSS) or execute arbitrary PHP code via a crafted text field.
Published Feb 11, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain sensitive information.
Published Feb 6, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Varnish HTTP cache before 3.0.4: ACL bug
Published Feb 12, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Kernel/Modules/AgentTicketWatcher.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.21, 3.1.x before 3.1.17, and 3.2.x before 3.2.8 does not properly restrict tickets, which allows remote attackers with a valid agent login to read restricted tickets via a crafted URL involving the ticket split mechanism.
Published Feb 21, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The server in IBM SPSS Collaboration and Deployment Services 4.x before 4.2.1.3 IF3, 5.x before 5.0 FP3, and 6.x before 6.0 IF1 allows remote attackers to read arbitrary files via an unspecified HTTP request.
Published Feb 1, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not validate URLs in Cookie headers before using them in redirects, which has unspecified impact and remote attack vectors.
Published Feb 13, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
Published Feb 13, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Potplayer prior to 1.5.39659: DLL Loading Arbitrary Code Execution Vulnerability
Published Feb 11, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not send the appropriate HTTP response headers to prevent unwanted caching by a web browser, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.
Published Feb 13, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in the JoomShopping (com_joomshopping) component before 4.3.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the user_name parameter to index.php.
Published Feb 11, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote malicious user execute arbitrary code.
Published Feb 17, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A Denial of Service (infinite loop) exists in OpenSIPS before 1.10 in lookup.c.
Published Feb 17, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Invision Power Board (IPB) through 3.x allows admin account takeover leading to code execution.
Published Feb 12, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A Privilege Escalation Vulnerability exists in Sprite Software Spritebud 1.3.24 and 1.3.28 and Backup 2.5.4105 and 2.5.4108 on LG Android smartphones due to a race condition in the spritebud daemon, which could let a local malicious user obtain root privileges.
Published Feb 12, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
SUSE Studio Onsite 1.3.x before 1.3.6 and SUSE Studio Extension for System z 1.3 uses "static" secret tokens, which has unspecified impact and vectors.
Published Feb 26, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload
Published Feb 11, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Kernel/Modules/AgentTicketPhone.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.20, 3.1.x before 3.1.16, and 3.2.x before 3.2.7, and OTRS ITSM 3.0.x before 3.0.8, 3.1.x before 3.1.9, and 3.2.x before 3.2.5 does not properly restrict tickets, which allows remote attackers with a valid agent login to read restricted tickets via a crafted URL involving the ticket split mechanism.
Published Feb 21, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
SQL injection vulnerability in Boonex Dolphin before 7.1.3 allows remote authenticated users to execute arbitrary SQL commands via the 'pathes' parameter in 'categories.php'.
Published Feb 6, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The web interface in VideoLAN VLC media player before 2.0.7 has no access control which allows remote attackers to view directory listings via the 'dir' command or issue other commands without authenticating.
Published Feb 6, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
ProjectPier 0.8.8 has a Remote Information Disclosure Weakness because of the lack of the HttpOnly cookie flag
Published Feb 7, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple cross-site scripting (XSS) vulnerabilities in Xaraya 2.4.0-b1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id, (2) interface, (3) name, or (4) tabmodule parameter to index.php.
Published Feb 5, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability
Published Feb 7, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability
Published Feb 7, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution
Published Feb 7, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
ProjectPier 0.8.8 has stored XSS
Published Feb 7, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
ProjectPier 0.8.8 does not use the Secure flag for cookies
Published Feb 7, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.
Published Feb 6, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which makes it easier for man-in-the-middle attackers to obtain plaintext secret values by observing length differences during a series of guesses in which a string in an HTTP request URL potentially matches an unknown string in an HTTP response body, aka a "BREACH" attack, a different issue than CVE-2012-4929.
Published Feb 21, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Nitro Pro 7.5.0.22 and earlier and Nitro Reader 2.5.0.36 and earlier allow remote attackers to execute arbitrary code via a crafted PDF file.
Published Feb 8, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Nitro Pro 7.5.0.29 and earlier and Nitro Reader 2.5.0.45 and earlier allow remote attackers to execute arbitrary code via a crafted PDF file.
Published Feb 8, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A Code Execution Vulnerability exists in UMPlayer 0.98 in wintab32.dll due to insufficient path restrictions when loading external libraries. which could let a malicious user execute arbitrary code.
Published Feb 12, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
TRENDnet TEW-812DRU router allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) wan network prefix to internet/ipv6.asp; (2) remote port to adm/management.asp; (3) pptp username, (4) pptp password, (5) ip, (6) gateway, (7) l2tp username, or (8) l2tp password to internet/wan.asp; (9) NtpDstStart, (10) NtpDstEnd, or (11) NtpDstOffset to adm/time.asp; or (12) device url to adm/management.asp. NOTE: vectors 9, 10, and 11 can be exploited by unauthenticated remote attackers by leveraging CVE-2013-3098.
Published Feb 4, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple SQL injection vulnerabilities in Exponent CMS before 2.2.0 release candidate 1 allow remote attackers to execute arbitrary SQL commands via the (1) src or (2) username parameter to index.php.
Published Feb 11, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access.
Published Feb 18, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple cross-site request forgery (CSRF) vulnerabilities in TRENDnet TEW-812DRU router with firmware before 1.0.9.0 allow remote attackers to hijack the authentication of administrators for requests that (1) change admin credentials in a request to setSysAdm.cgi, (2) enable remote management or (3) enable port forwarding in an Apply action to uapply.cgi, or (4) have unspecified impact via a request to setNTP.cgi. NOTE: some of these details are obtained from third party information.
Published Feb 4, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
D-Link DIR865L v1.03 suffers from an "Unauthenticated Hardware Linking" vulnerability.
Published Feb 7, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication using "Javascript debugging."
Published Feb 7, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Linksys WRT310Nv2 2.0.0.1 is vulnerable to XSS.
Published Feb 7, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An ActiveX control in IcoLaunch.dll in Mitsubishi Electric Automation MC-WorX Suite 8.02 allows user-assisted remote attackers to execute arbitrary programs via a crafted HTML document in conjunction with a Login Client button click.
Published Feb 24, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Buffer overflow in the Launcher in IBM WebSphere Transformation Extender 8.4.x before 8.4.0.4 allows local users to cause a denial of service (process crash or Admin Console command-stream outage) via unspecified vectors.
Published Feb 6, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Use-after-free vulnerability in SumatraPDF Reader 2.x before 2.2.1 allows remote attackers to execute arbitrary code via a crafted PDF file.
Published Feb 8, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
MatrikonOPC SCADA DNP3 OPC Server 1.2.2.0 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed DNP3 packet.
Published Feb 13, 2014 · Updated Aug 6, 2024