CWE:
 

Topic
Date
Author
Med.
Landesk Management Suite 9.5 RFI / CSRF
21.04.2015
Alex Haynes


CVEMAP Search Results

CVE
Details
Description
2020-08-11
Medium
CVE-2020-13175

Vendor: Teradici
Software: Cloud access...
 

 
The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to April 20, 2020 (v15 and earlier for Cloud Access Connector) contains a local file inclusion vulnerability which allows an unauthenticated remote attacker to leak LDAP credentials via a specially crafted HTTP request.

 
2020-04-01
Medium
CVE-2020-10865

Updating...
 

 
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to make arbitrary changes to the Components section of the Stats.ini file via RPC from a Low Integrity process.

 
2020-01-29
Medium
CVE-2013-3321

Vendor: Netapp
Software: Oncommand sy...
 

 
NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to include arbitrary files through specially crafted requests to the "diagnostic" page using the SnapMirror log path parameter.

 
2020-01-28
Low
CVE-2013-4582

Vendor: Gitlab
Software: Gitlab
 

 
The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to include information from local files into the metadata of a Git repository via the web interface.

 
2020-01-22
Medium
CVE-2012-4919

Vendor: Gallery project
Software: Gallery
 

 
Gallery Plugin1.4 for WordPress has a Remote File Include Vulnerability

 
2020-01-08
Low
CVE-2019-17014

Vendor: Mozilla
Software: Firefox
 

 
If an image had not loaded correctly (such as when it is not actually an image), it could be dragged and dropped cross-domain, resulting in a cross-origin information leak. This vulnerability affects Firefox < 71.

 
2019-09-27
Low
CVE-2019-11742

Vendor: Mozilla
Software: Firefox
 

 
A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and a &lt;canvas&gt; element due to an error in how same-origin policy is applied to cached image content. The resulting same-origin policy violation could allow for data theft. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1.

 
2018-12-20
Medium
CVE-2018-17246

Vendor: Elasticsearch
Software: Kibana
 

 
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.

 
2018-11-28
Medium
CVE-2018-12120

Vendor: Nodejs
Software: Node.js
 

 
Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any interface by default: When the debugger is enabled with `node --debug` or `node debug`, it listens to port 5858 on all interfaces by default. This may allow remote computers to attach to the debug port and evaluate arbitrary JavaScript. The default interface is now localhost. It has always been possible to start the debugger on a specific interface, such as `node --debug=localhost`. The debugger was removed in Node.js 8 and replaced with the inspector, so no versions from 8 and later are vulnerable.

 
2018-10-29
High
CVE-2018-18387

Vendor: Playsms project
Software: Playsms
 

 
playSMS through 1.4.2 allows Privilege Escalation through Daemon abuse.

 

 


Copyright 2021, cxsecurity.com

 

Back to Top