[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

252588

 
 

909

 
 

196930

 
 

282

 
 
Paid content will be excluded from the download.

Filter
Matches : 31447 Download | Alert*

An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious XML content containing a reference to an external entity. An attacker who successfully exploited this vulnerability could read arbitrary files via an XML external entity declaration. To exploit the vulnerability, an attacker must entice a user on an affected SSMS server to open a ...

The host is installed with NetMechanica NetDecision before 4.6.1 and is prone to an information disclosure vulnerability. A flaw is present in the application, which fails to handle an invalid version number. Successful exploitation could allow attackers to obtain the source code of NetDecision script files with a .nd extension.

The host is installed with NetMechanica NetDecision before 4.6.1 and is prone an information disclosure vulnerability. A flaw is present in the application, which fails to handle a request with a trailing "?". Successful exploitation could allow attackers to obtain the installation path.

The host is installed with Symantec Altiris WISE Package Studio before 8.0MR1 and is prone to multiple sql injection vulnerabilities. The flaws are present in the application, which fails to handle unspecified vectors. Successful exploitation could allow remote attackers to execute arbitrary SQL commands.

The host is installed with Team Foundation 2018 Server Update 1.1 or Update 3 and is prone to a cross-site scripting vulnerability. The application fails to properly sanitize user provided input. On successful exploitation, an attacker could send a specially crafted payload to the Team Foundation Server, which will get executed in the context of the user every time a user visits the compromised pa ...

An information disclosure vulnerability exists in Lync 2013. An attacker who exploited it could read arbitrary files on the victim's machine. To exploit the vulnerability, an attacker needs to instantiate a conference and modify the meeting link with malicious content and send the link to a victim. The update addresses the vulnerability by changing how the URL is being resolved.

An information disclosure vulnerability exists when the Windows Remote Desktop Protocol (RDP) fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user's system. To exploit this vulnerability, an attacker would have to connect remotely to an affected system and run a specially crafted application.

Host is installed with Kaspersky Anti-Virus 2019 before Patch F and is prone to an Information exposure vulnerability. A flaw is present in the application, which fails to properly handle a specially crafted webpage. Successful exploitation allows an attacker to potentially disclose unique Product ID.

The host is installed with Pro-face WinGP PC Runtime 3.01.100 or earlier and is prone to information disclosure vulnerability. A flaw is present in the application, which fails to handle a crafted packet with a certain opcode. Successful exploitation could allow remote attackers to obtain sensitive information from daemon memory crash.

The host is installed with IBM Rational ClearQuest 7.1.1 before 7.1.1.9 or 7.1.2 before 7.1.2.6 and is prone to SQL injection vulnerability. A flaw is present in the application, which fails to handle certain fields in the Maintenance tool. Successful exploitation allows remote attackers to execute arbitrary SQL commands by leveraging an error in the user-database upgrade feature.


Pages:      Start    3063    3064    3065    3066    3067    3068    3069    3070    3071    3072    3073    3074    3075    3076    ..   3144

© SecPod Technologies