Page 4 of 35 results (0.004 seconds)

CVSS: 7.5EPSS: 2%CPEs: 1EXPL: 2

27 Jul 2001 — Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent HTML SCRIPT filtering via the UNICODE encoding of SCRIPT tags within the HTML document. • https://www.exploit-db.com/exploits/20891 •

CVSS: 5.5EPSS: 0%CPEs: 4EXPL: 0

09 Jan 2001 — ghostscript before 5.10-16 allows local users to overwrite files of other users via a symlink attack. • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000343 •

CVSS: 7.8EPSS: 0%CPEs: 5EXPL: 0

09 Jan 2001 — ghostscript before 5.10-16 uses an empty LD_RUN_PATH environmental variable to find libraries in the current directory, which could allow local users to execute commands as other users by placing a Trojan horse library into a directory from which another user executes ghostscript. • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000343 •

CVSS: 4.6EPSS: 0%CPEs: 1EXPL: 1

04 May 2000 — The Aladdin Knowledge Systems eToken device allows attackers with physical access to the device to obtain sensitive information without knowing the PIN of the owner by resetting the PIN in the EEPROM. • https://www.exploit-db.com/exploits/19894 •

CVSS: 9.8EPSS: 1%CPEs: 2EXPL: 0

31 Aug 1995 — The ghostscript command with the -dSAFER option allows remote attackers to execute commands. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0155 •