Lucene search

K

Studio Security Vulnerabilities

cve
cve

CVE-2000-0449

Omnis Studio 2.4 uses weak encryption (trivial encoding) for encrypting database fields.

7.1AI Score

0.01EPSS

2000-06-15 04:00 AM
26
cve
cve

CVE-2004-2335

The Macromedia installers and e-licensing client on Mac OS X, as used for Macromedia Contribute 2, Director, Dreamweaver, Fireworks, Flash, and Studio, install the AuthenticationService setuid and writable by other users, which allows local users to gain privileges by modifying the program.

7AI Score

0.0004EPSS

2005-08-16 04:00 AM
28
cve
cve

CVE-2005-4708

Adobe Macromedia MX 2004 products, Captivate, Contribute 2, Contribute 3, and eLicensing client install the Macromedia Licensing Service with the Users group permitted to configure the service, including the path to executable, which allows local users to execute arbitrary code as Local System.

7.7AI Score

0.001EPSS

2006-02-02 11:00 AM
23
cve
cve

CVE-2009-2968

Directory traversal vulnerability in a support component in the web interface in VMware Studio 2.0 public beta before build 1017-185256 allows remote attackers to upload files to arbitrary locations via unspecified vectors.

6.9AI Score

0.008EPSS

2009-09-02 05:30 PM
29
cve
cve

CVE-2010-2427

VMware Studio 2.0 does not properly write to temporary files, which allows local users to gain privileges via unspecified vectors.

6.6AI Score

0.0004EPSS

2010-07-22 05:43 AM
21
cve
cve

CVE-2010-2667

Multiple unspecified vulnerabilities in the Virtual Appliance Management Infrastructure (VAMI) in VMware Studio 2.0 allow remote authenticated users to execute arbitrary commands via vectors involving (1) the Studio virtual appliance or (2) a virtual appliance created by the Studio virtual applianc...

7.4AI Score

0.005EPSS

2010-07-22 05:43 AM
18
cve
cve

CVE-2011-4315

Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long response.

7.6AI Score

0.006EPSS

2011-12-08 08:55 PM
60
cve
cve

CVE-2018-7472

INVT Studio 1.2 allows remote attackers to cause a denial of service during import operations.

5.5CVSS

5.5AI Score

0.001EPSS

2018-02-25 07:29 AM
22
cve
cve

CVE-2020-25802

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy scripting. This issue affects: Crafter Software Crafter CMS 3.0 versions prior to 3.0.27; 3.1 versions prior to 3.1.7.

7.2CVSS

7AI Score

0.001EPSS

2020-10-06 02:15 PM
36
cve
cve

CVE-2020-25803

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker template exposed objects. This issue affects: Crafter Software Crafter CMS 3.0 versions prior to 3.0.27; 3.1 versions prior to ...

7.2CVSS

7.1AI Score

0.001EPSS

2020-10-06 03:15 PM
41
cve
cve

CVE-2021-22289

Improper Input Validation vulnerability in the project upload mechanism in B&R Automation Studio version >=4.0 may allow an unauthenticated network attacker to execute code.

9.8CVSS

9.5AI Score

0.003EPSS

2022-08-11 03:15 PM
33
5
cve
cve

CVE-2022-21815

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for private IOCTLs where a NULL pointer dereference in the kernel, created within user mode code, may lead to a denial of service in the form of a system crash.

5.5CVSS

5.3AI Score

0.0004EPSS

2022-02-07 08:15 PM
49
4
cve
cve

CVE-2023-31444

In Talend Studio before 7.3.1-R2022-10 and 8.x before 8.0.1-R2022-09, microservices allow unauthenticated access to the Jolokia endpoint of the microservice. This allows for remote access to the JVM via the Jolokia JMX-HTTP bridge.

7.5CVSS

7.6AI Score

0.002EPSS

2023-04-28 09:15 PM
13
cve
cve

CVE-2023-38334

Omnis Studio 10.22.00 has incorrect access control. It advertises an irreversible feature for locking classes within Omnis libraries: it should be no longer possible to delete, view, change, copy, rename, duplicate, or print a locked class. Due to implementation issues, locked classes in Omnis libr...

6.5CVSS

6.4AI Score

0.002EPSS

2023-07-20 06:15 PM
20
cve
cve

CVE-2023-38335

Omnis Studio 10.22.00 has incorrect access control. It advertises a feature for making Omnis libraries "always private" - this is supposed to be an irreversible operation. However, due to implementation issues, "always private" Omnis libraries can be opened by the Omnis Studio browser by bypassing ...

5.3CVSS

5.2AI Score

0.002EPSS

2023-07-20 06:15 PM
31
cve
cve

CVE-2023-39967

WireMock is a tool for mocking HTTP services. When certain request URLs like “@127.0.0.1:1234" are used in WireMock Studio configuration fields, the request might be forwarded to an arbitrary service reachable from WireMock’s instance. There are 3 identified potential attack vectors: via “TestReque...

10CVSS

9.4AI Score

0.001EPSS

2023-09-06 09:15 PM
22
cve
cve

CVE-2023-41327

WireMock is a tool for mocking HTTP services. WireMock can be configured to only permit proxying (and therefore recording) to certain addresses. This is achieved via a list of allowed address rules and a list of denied address rules, where the allowed list is evaluated first. Until WireMock Webhook...

5.4CVSS

6.2AI Score

0.001EPSS

2023-09-06 09:15 PM
2431
cve
cve

CVE-2023-41329

WireMock is a tool for mocking HTTP services. The proxy mode of WireMock, can be protected by the network restrictions configuration, as documented in Preventing proxying to and recording from specific target addresses. These restrictions can be configured using the domain names, and in such a case...

6.6CVSS

6.4AI Score

0.001EPSS

2023-09-06 09:15 PM
41