Skip to main content

Vendor archive

thomsonreuters CVEs

Beta · best-effort

8 CVEs tagged to vendor thomsonreuters4 Critical, 4 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2019-10679

Published Sep 3, 2020

Thomson Reuters Eikon 4.0.42144 allows all local users to modify the service executable file because of weak %PROGRAMFILES(X86)%\Thomson Reuters\Eikon permissions.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5952

Published Jan 15, 2020

Directory traversal vulnerability in Thomson Reuters for FATCA before 5.2 allows remote attackers to execute arbitrary files via the item parameter.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-5951

Published Jan 6, 2020

A file upload issue exists in the specid parameter in Thomson Reuters FATCH before 5.2, which allows malicious users to upload arbitrary PHP files to the web root and execute syst…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-14607

Published Jul 26, 2018

Thomson Reuters UltraTax CS 2017 on Windows, in a client/server configuration, transfers customer records and bank account numbers in cleartext over SMBv2, which allows attackers…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9141

Published Dec 3, 2014

The installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which allows local users to execute arbitrary code by modifying this…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1