6 results (0.006 seconds)

CVSS: 5.5EPSS: 0%CPEs: 2EXPL: 0

25 Oct 2015 — HP Asset Manager 9.40 and 9.41 before 9.41.11103 P4-rev1 and 9.50 before 9.50.11925 P3 allows local users to obtain sensitive information via unspecified vectors. HP Asset Manager 9.40 y 9.41 en versiones anteriores a 9.41.11103 P4-rev1 y 9.50 en versiones anteriores a 9.50.11925 P3 permite a usuarios locales obtener información sensible a través de vectores no especificados. A potential security vulnerability has been identified with HP Asset Manager Web UI client. The vulnerability could be exploited to a... • http://www.securityfocus.com/bid/77303 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 9.8EPSS: 1%CPEs: 2EXPL: 0

08 Mar 2008 — MRcgi/MRProcessIncomingForms.pl in Numara FootPrints 8.1 on Linux allows remote attackers to execute arbitrary code via shell metacharacters in the PROJECTNUM parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. MRcgi/MRProcessIncomingForms.pl en Numara FootPrints 8.1 para Linux permite a atacantes remotos ejecutar código de su elección a través de metacaracteres de consola en el parámetro PROJECTNUM. NOTA: el origen de esta informació... • http://secunia.com/advisories/28659 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 6.1EPSS: 0%CPEs: 2EXPL: 0

08 Mar 2008 — Cross-site scripting (XSS) vulnerability in Numara FootPrints for Linux 8.1 allows remote attackers to inject arbitrary web script or HTML via the Title form field when setting an appointment. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Numara FootPrints para Linux 8.1 permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través del cam... • http://secunia.com/advisories/28659 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.8EPSS: 0%CPEs: 4EXPL: 0

23 Jul 2007 — Centennial Discovery 2006 Feature Pack 1, which is used by (1) Numara Asset Manager 8.0 and (2) Symantec Discovery 6.5, uses insecure permissions on certain directories, which allows local users to gain privileges. Centennial Discovery 2006 Feature Pack 1, el cual es usado por (1) Numara Asset Manager 8.0 y (2) Symantec Discovery 6.5, utiliza permisos no seguros sobre ciertos directorios, el cual permite a usuarios locales ganar privilegios. • http://secunia.com/advisories/25354 •

CVSS: 9.8EPSS: 11%CPEs: 3EXPL: 0

06 Jun 2007 — Stack-based buffer overflow in XferWan.exe as used in multiple products including (1) Symantec Discovery 6.5, (2) Numara Asset Manager 8.0, and (3) Centennial UK Ltd Discovery 2006 Feature Pack, allows remote attackers to execute arbitrary code via a long request. NOTE: this might be a reservation duplicate of CVE-2007-1173. Desbordamiento de búfer basado en pila en el XferWan.exe como el utilizado en múltiples productos incluidos (1) Symantec Discovery 6.5, (2) Numara Asset Manager 8.0 y (3) Centennial UK ... • http://dvlabs.tippingpoint.com/advisory/TPTI-07-10 •

CVSS: 10.0EPSS: 22%CPEs: 3EXPL: 0

16 May 2007 — Multiple buffer overflows in the CentennialIPTransferServer service (XFERWAN.EXE), as used by (1) Centennial Discovery 2006 Feature Pack 1, (2) Numara Asset Manager 8.0, and (3) Symantec Discovery 6.5, allow remote attackers to execute arbitrary code via long strings in a crafted TCP packet. Múltiples desbordamientos de búfer en el servicio CentennialIPTransferServer (XFERWAN.EXE), como el usado por (1) Centennial Discovery 2006 Feature Pack 1, (2) Numara Asset Manager 8.0, y (3) Symantec Discovery 6.5, per... • http://osvdb.org/35076 •