
CVE-2018-3854
https://notcve.org/view.php?id=CVE-2018-3854
03 Dec 2018 — An exploitable information disclosure vulnerability exists in the password protection functionality of Quicken Deluxe 2018 for Mac version 5.2.2. A specially crafted sqlite3 request can cause the removal of the password protection, allowing an attacker to access and modify the data without knowing the password. An attacker needs to have access to the password-protected files to trigger this vulnerability. Existe una vulnerabilidad de divulgación de información explotable en la funcionalidad de protección de... • https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0537 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2007-6387 – Vantage Linguistics AnswerWorks 4 - API ActiveX Control Buffer Overflow
https://notcve.org/view.php?id=CVE-2007-6387
15 Dec 2007 — Multiple stack-based buffer overflows in the awApi4.AnswerWorks.1 ActiveX control in awApi4.dll 4.0.0.42, as used by Vantage Linguistics AnswerWorks, and Intuit Clearly Bookkeeping, ProSeries, QuickBooks, Quicken, QuickTax, and TurboTax, allow remote attackers to execute arbitrary code via long arguments to the (1) GetHistory, (2) GetSeedQuery, (3) SetSeedQuery, and possibly other methods. NOTE: some of these details are obtained from third party information. Múltiples desbordamientos de búfer basados en pi... • https://www.exploit-db.com/exploits/4825 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •