Skip to main content

Vendor/product archive

sybase / easerver CVEs

Beta · best-effort

8 CVEs tagged to sybase / easerver1 Critical, 1 High, 5 Medium, 1 Low, 0 Unrated.

CVE-2012-4340

Published Aug 15, 2012

Cross-site scripting (XSS) vulnerability in Sybase EAServer before 6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2474

Published Jun 9, 2011

Directory traversal vulnerability in the HTTP Server in Sybase EAServer 6.3.1 Developer Edition allows remote attackers to read arbitrary files via a /.\../\../\ sequence in a pat…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2006-2539

Published May 22, 2006

Sybase EAServer 5.0 for HP-UX Itanium, 5.2 for IBM AIX, HP-UX PA-RISC, Linux x86, and Sun Solaris SPARC, and 5.3 for Sun Solaris SPARC does not properly protect passwords when the…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-1829

Published Apr 19, 2006

EAServer Manager in Sybase EAServer 5.2 and 5.3 allows remote authenticated users, possibly guests, to obtain password credentials of arbitrary users via unspecified vectors invol…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2297

Published Jul 19, 2005

Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary code via a large javascript parameter.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1861

Published Dec 31, 2002

Sybase Enterprise Application Server 4.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configur…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1