Lucene search

K

Progress Security Vulnerabilities

cve
cve

CVE-2023-40954

A SQL injection vulnerability in Grzegorz Marczynski Dynamic Progress Bar (aka web_progress) v. 11.0 through 11.0.2, v12.0 through v12.0.2, v.13.0 through v13.0.2, v.14.0 through v14.0.2.1, v.15.0 through v15.0.2, and v16.0 through v16.0.2.1 allows a remote attacker to gain privileges via the...

9.8CVSS

9.8AI Score

0.001EPSS

2023-12-15 01:15 AM
4
cve
cve

CVE-2023-23699

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Chris Reynolds Progress Bar plugin <= 2.2.1...

6.5CVSS

5.5AI Score

0.0005EPSS

2023-05-29 03:15 PM
14
cve
cve

CVE-2021-24752

Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPress plugin before 2.3, Header Enhancement...

5.7CVSS

5.2AI Score

0.001EPSS

2021-10-18 02:15 PM
22
cve
cve

CVE-2021-2271

Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Resource Exceptions). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work....

8.1CVSS

8.1AI Score

0.001EPSS

2021-04-22 10:15 PM
36
3
cve
cve

CVE-2004-2743

upload.cgi in Mega Upload Progress Bar before 1.45 allows remote attackers to copy or overwrite arbitrary files via unspecified parameters related to names of uploaded...

7.2AI Score

0.008EPSS

2007-10-09 10:00 AM
19
cve
cve

CVE-2007-2417

Heap-based buffer overflow in _mprosrv.exe in Progress Software Progress 9.1E and OpenEdge 10.1x, as used by the RSA Authentication Manager 6.0 and 6.1, SecurID Appliance 2.0, ACE/Server 5.2, and possibly other products, allows remote attackers to execute arbitrary code via crafted packets. NOTE:.....

8.1AI Score

0.126EPSS

2007-07-15 09:30 PM
20
cve
cve

CVE-2007-2506

WebSpeed 3.x in OpenEdge 10.x in Progress Software Progress 9.1e, and certain other 9.x versions, allows remote attackers to cause a denial of service (infinite loop and daemon hang) via a messenger URL that invokes _edit.r with no additional parameters, as demonstrated by requests for cgiip.exe...

6.7AI Score

0.089EPSS

2007-05-04 01:19 AM
22
cve
cve

CVE-2006-6361

Heap-based buffer overflow in the uploadprogress_php_rfc1867_file function in uploadprogress.c in Bitflux Upload Progress Meter before 8276 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via crafted HTTP POST fileupload...

8.4AI Score

0.036EPSS

2006-12-07 11:28 AM
17
cve
cve

CVE-2001-1127

Buffer overflow in Progress database 8.3D and 9.1C could allow a local user to execute arbitrary code via (1) _proapsv, (2) _mprosrv, (3) _mprshut, (4) orarx, (5) sqlcpp, (6) _probrkr, (7) _sqlschema and (8)...

7.9AI Score

0.0004EPSS

2002-03-15 05:00 AM
31
cve
cve

CVE-2001-1128

Buffer overflow in Progress database 8.3D and 9.1C allows local users to execute arbitrary code via long entries in files that are specified by the (1) PROMSGS or (2) PROTERMCAP environment...

7.9AI Score

0.0004EPSS

2002-03-15 05:00 AM
16
cve
cve

CVE-2001-1129

Format string vulnerabilities in (1) _probuild, (2) _dbutil, (3) _mprosrv, (4) _mprshut, (5) _proapsv, (6) _progres, (7) _proutil, (8) _rfutil and (9) prolib in Progress database 9.1C allows a local user to execute arbitrary code via format string specifiers in the file used by the PROMSGS...

7.8AI Score

0.001EPSS

2002-03-15 05:00 AM
18