Unknown · CVSS Not scored
ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or process-zip-download.php, or add_user_form_* parameters to users-add.php.
Published Oct 28, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional arguments supplied after --create, allowing users to manipulate commands and perform command injection as root.
Published Oct 24, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Application API script. It should not be run by users directly. It uses star to backup and restore data. It runs binaries with root permissions when parsing the command line argument --star-path.
Published Oct 24, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the request parameter files, clients.php with the request parameter selected_clients, clients.php with the request parameter status, process-zip-download.php with the request parameter file, or home-log.php with the request parameter action.
Published Oct 28, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php.
Published Oct 28, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string.
Published Oct 28, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
D-Link DSL-2740E 1.00_BG_20150720 devices are prone to persistent XSS attacks in the username and password fields: a remote unauthenticated user may craft logins and passwords with script tags in them. Because there is no sanitization in the input fields, an unaware logged-in administrator may be a victim when checking the router logs.
Published Oct 31, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In Redmine before 3.2.3, there are stored XSS vulnerabilities affecting Textile and Markdown text formatting, and project homepages.
Published Oct 18, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).
Published Oct 24, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other products) allows remote attackers to inject arbitrary web script or HTML via a field that contains an exception message.
Published Oct 23, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.
Published Oct 12, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
There is a NULL Pointer Access in function imagetopnm of convert.c:1943(jp2) of OpenJPEG 2.1.2. image->comps[compno].data is not assigned a value after initialization(NULL). Impact is Denial of Service.
Published Oct 30, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Heap Buffer Over-read in function imagetotga of convert.c(jp2):942 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.
Published Oct 30, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Floating Point Exception (aka FPE or divide by zero) in opj_pi_next_cprl function in openjp2/pi.c:523 in OpenJPEG 2.1.2.
Published Oct 29, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
NULL Pointer Access in function imagetopnm of convert.c(jp2):1289 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.
Published Oct 30, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
NULL Pointer Access in function imagetopnm of convert.c:2226(jp2) in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.
Published Oct 30, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
There is a NULL pointer dereference in function imagetobmp of convertbmp.c:980 of OpenJPEG 2.1.2. image->comps[0].data is not assigned a value after initialization(NULL). Impact is Denial of Service.
Published Oct 30, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Heap Buffer Overflow (WRITE of size 4) in function pnmtoimage of convert.c:1719 in OpenJPEG 2.1.2.
Published Oct 30, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A use-after-free in nsINode::ReplaceOrInsertBefore during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Firefox < 50.
Published Oct 18, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Improper handling of a repeating VRAT chunk in qcpfformat.dll allows attackers to cause a Null pointer dereference and crash in RealNetworks RealPlayer 18.1.5.705 through a crafted .QCP media file.
Published Oct 28, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Artifex Software, Inc. MuJS before a5c747f1d40e8d6659a37a8d25f13fb5acf8e767 allows context-dependent attackers to obtain sensitive information by using the "opname in crafted JavaScript file" approach, related to an "Out-of-Bounds read" issue affecting the jsC_dumpfunction function in the jsdump.c component.
Published Oct 28, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Unauthorized redirect vulnerability in Citrix NetScaler ADC before 10.1 135.8, 10.5 61.11, 11.0 65.31/65.35F and 11.1 47.14 allows a remote attacker to steal session cookies of a legitimate AAA user via manipulation of Host header.
Published Oct 28, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In Bitcoin Knots v0.11.0.ljr20150711 through v0.13.0.knots20160814 (fixed in v0.13.1.knots20161027), the debug console stores sensitive information including private keys and the wallet passphrase in its persistent command history.
Published Oct 28, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to access files within the container filesystem or mounted volumes.
Published Oct 28, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to execute arbitrary code via a crafted BMP image embedded in the XFA stream in a PDF document, aka "Data from Faulting Address may be used as a return value starting at FOXITREADER."
Published Oct 31, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In Botan 1.11.29 through 1.11.32, RSA decryption with certain padding options had a detectable timing channel which could given sufficient queries be used to recover plaintext, aka an "OAEP side channel" attack.
Published Oct 28, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF image embedded in the XFA stream in a PDF document, aka "Read Access Violation starting at FoxitReader."
Published Oct 31, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image, aka "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at ConvertToPDF_x86!CreateFXPDFConvertor."
Published Oct 31, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Heap buffer overflow (Out-of-Bounds write) vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows allows remote attackers to execute arbitrary code via a crafted JPEG2000 image embedded in a PDF document, aka a "corrupted suffix pattern" issue.
Published Oct 31, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The thumbnail shell extension plugin (FoxitThumbnailHndlr_x86.dll) in Foxit Reader and PhantomPDF before 8.1 on Windows allows remote attackers to cause a denial of service (out-of-bounds write and application crash) via a crafted JPEG2000 image embedded in a PDF document, aka an "Exploitable - Heap Corruption" issue.
Published Oct 31, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Foxit Reader for Mac 2.1.0.0804 and earlier and Foxit Reader for Linux 2.1.0.0805 and earlier suffered from a vulnerability where weak file permissions could be exploited by attackers to execute arbitrary code. After the installation, Foxit Reader's core files were world-writable by default, allowing an attacker to overwrite them with backdoor code, which when executed by privileged user would result in Privilege Escalation, Code Execution, or both.
Published Oct 31, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Stack-based buffer overflow in the brcmf_cfg80211_start_ap function in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux kernel before 4.7.5 allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via a long SSID Information Element in a command to a Netlink socket.
Published Oct 16, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.
Published Oct 12, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The XFS subsystem in the Linux kernel through 4.8.2 allows local users to cause a denial of service (fdatasync failure and system hang) by using the vfs syscall group in the trinity program, related to a "page lock order bug in the XFS seek hole/data implementation."
Published Oct 16, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The IP stack in the Linux kernel before 4.6 allows remote attackers to cause a denial of service (stack consumption and panic) or possibly have unspecified other impact by triggering use of the GRO path for packets with tunnel stacking, as demonstrated by interleaved IPv4 headers and GRE headers, a related issue to CVE-2016-7039.
Published Oct 16, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
SQL injection vulnerability in Siemens Automation License Manager (ALM) before 5.3 SP3 Update 1 allows remote attackers to execute arbitrary SQL commands via crafted traffic to TCP port 4410.
Published Oct 13, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
docker2aci <= 0.12.3 has an infinite loop when handling local images with cyclic dependency chain.
Published Oct 28, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check later.
Published Oct 28, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Buffer overflow in the zmq interface in csp_if_zmqhub.c in the libcsp library v1.4 and earlier allows hostile computers connected via a zmq interface to execute arbitrary code via a long packet.
Published Oct 28, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Buffer overflow in the csp_sfp_recv_fp in csp_sfp.c in the libcsp library v1.4 and earlier allows hostile components with network access to the SFP underlying network layers to execute arbitrary code via specially crafted SFP packets.
Published Oct 28, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
CSRF of synchronization form in Yandex Browser for desktop before version 16.6 could be used by remote attacker to steal saved data in browser profile.
Published Oct 26, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Siemens Automation License Manager (ALM) before 5.3 SP3 Update 1 allows remote attackers to cause a denial of service (ALM service outage) via crafted packets to TCP port 4410.
Published Oct 13, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve database information or read local system files via MySQL's LOAD_FILE.
Published Oct 28, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to steal session IDs of logged in users when the current sessions are viewed by an administrator.
Published Oct 28, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Buffer overflow in the csp_can_process_frame in csp_if_can.c in the libcsp library v1.4 and earlier allows hostile components connected to the canbus to execute arbitrary code via a long csp packet.
Published Oct 28, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
XSS in Yandex Browser Translator in Yandex browser for desktop for versions from 15.12 to 16.2 could be used by remote attacker for evaluation arbitrary javascript code.
Published Oct 26, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Siemens Automation License Manager (ALM) before 5.3 SP3 allows remote attackers to write to files, rename files, create directories, or delete directories via crafted packets.
Published Oct 13, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple GET parameters in the vulnerability scan scheduler of AlienVault OSSIM and USM before 5.3.2 are vulnerable to reflected XSS.
Published Oct 28, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vulnerabilities allow arbitrary PHP code execution via magic methods in included classes.
Published Oct 28, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 15.12.0 to 16.2 could be used by remote attacker for brute-forcing passwords from important web-resource with special JavaScript.
Published Oct 26, 2016 · Updated Aug 6, 2024