Total
260815 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2005-0269 | 1 Sir | 1 Gnuboard | 2024-02-02 | 7.5 HIGH | 9.8 CRITICAL |
The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attackers to upload arbitrary files via file extensions that include uppercase letters. | |||||
CVE-2019-10743 | 1 Archiver Project | 1 Archiver | 2024-02-02 | 5.8 MEDIUM | 5.5 MEDIUM |
All versions of archiver allow attacker to perform a Zip Slip attack via the "unarchive" functions. It is exploited using a specially crafted zip archive, that holds path traversal filenames. When exploited, a filename in a malicious archive is concatenated to the target extraction directory, which results in the final path ending up outside of the target folder. For instance, a zip may hold a file with a "../../file.exe" location and thus break out of the target folder. If an executable or a configuration file is overwritten with a file containing malicious code, the problem can turn into an arbitrary code execution issue quite easily. | |||||
CVE-2001-0766 | 1 Apache | 1 Http Server | 2024-02-02 | 7.5 HIGH | 9.8 CRITICAL |
Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters. | |||||
CVE-2001-0795 | 1 Perception | 1 Liteserve | 2024-02-02 | 5.0 MEDIUM | 7.5 HIGH |
Perception LiteServe 1.25 allows remote attackers to obtain source code of CGI scripts via URLs that contain MS-DOS conventions such as (1) upper case letters or (2) 8.3 file names. | |||||
CVE-2001-1238 | 1 Microsoft | 2 Windows 2000, Windows 2000 Terminal Services | 2024-02-02 | 4.6 MEDIUM | 7.8 HIGH |
Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot be stopped with the Task Manager. | |||||
CVE-2009-3781 | 2 Drupal, Quicksketch | 2 Drupal, Filefield | 2024-02-02 | 7.5 HIGH | N/A |
The filefield_file_download function in FileField 6.x-3.1, a module for Drupal, does not properly check node-access permissions for Drupal core private files, which allows remote attackers to access unauthorized files via unspecified vectors. | |||||
CVE-2024-24736 | 2024-02-02 | N/A | 7.5 HIGH | ||
The POP3 service in YahooPOPs (aka YPOPs!) 1.6 allows a remote denial of service (reboot) via a long string to TCP port 110, a related issue to CVE-2004-1558. | |||||
CVE-2024-0212 | 2024-02-02 | N/A | 6.5 MEDIUM | ||
The Cloudflare Wordpress plugin was found to be vulnerable to improper authentication. The vulnerability enables attackers with a lower privileged account to access data from the Cloudflare API. | |||||
CVE-2024-23790 | 2024-02-02 | N/A | 9.8 CRITICAL | ||
Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes. This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023 through 2023.1.1. | |||||
CVE-2024-23792 | 2024-02-02 | N/A | 6.5 MEDIUM | ||
When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. The attack requires a logged-in other user to know the UUID. While the legitimate user completes the comment, the malicious user can add more files to the comment. This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023.X through 2023.1.1. | |||||
CVE-2024-23791 | 2024-02-02 | N/A | 7.5 HIGH | ||
Insertion of debug information into log file during building the elastic search index allows reading of sensitive information from articles.This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023.X through 2023.1.1. | |||||
CVE-2015-3629 | 2 Docker, Opensuse | 2 Libcontainer, Opensuse | 2024-02-02 | 7.2 HIGH | 7.8 HIGH |
Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary file on the host system via a symlink attack in an image when respawning a container. | |||||
CVE-2023-29055 | 2024-02-02 | N/A | 7.5 HIGH | ||
In Apache Kylin version 2.0.0 to 4.0.3, there is a Server Config web interface that displays the content of file 'kylin.properties', that may contain serverside credentials. When the kylin service runs over HTTP (or other plain text protocol), it is possible for network sniffers to hijack the HTTP payload and get access to the content of kylin.properties and potentially the containing credentials. To avoid this threat, users are recommended to * Always turn on HTTPS so that network payload is encrypted. * Avoid putting credentials in kylin.properties, or at least not in plain text. * Use network firewalls to protect the serverside such that it is not accessible to external attackers. * Upgrade to version Apache Kylin 4.0.4, which filters out the sensitive content that goes to the Server Config web interface. | |||||
CVE-2024-1014 | 2024-02-02 | N/A | 7.5 HIGH | ||
Uncontrolled resource consumption vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could interrupt the availability of the administration panel by sending multiple ICMP packets. | |||||
CVE-2000-0342 | 1 Qualcomm | 1 Eudora | 2024-02-02 | 5.0 MEDIUM | 7.5 HIGH |
Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refers to the attachment, aka "Stealth Attachment." | |||||
CVE-2001-1042 | 1 Transsoft | 1 Broker Ftp Server | 2024-02-02 | 5.0 MEDIUM | 7.5 HIGH |
Transsoft Broker 5.9.5.0 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file. | |||||
CVE-2001-1043 | 1 Argosoft | 1 Ftp Server | 2024-02-02 | 5.0 MEDIUM | 7.5 HIGH |
ArGoSoft FTP Server 1.2.2.2 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file. | |||||
CVE-2024-1015 | 2024-02-02 | N/A | 9.8 CRITICAL | ||
Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could send different commands from the operating system to the system via the web configuration functionality of the device. | |||||
CVE-2024-22559 | 2024-02-02 | N/A | 5.4 MEDIUM | ||
LightCMS v2.0 is vulnerable to Cross Site Scripting (XSS) in the Content Management - Articles field. | |||||
CVE-2005-0587 | 1 Mozilla | 2 Firefox, Mozilla | 2024-02-02 | 2.6 LOW | 6.5 MEDIUM |
Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrites the file that was referenced in the first .LNK file. |