Vulnerabilities (CVE)

Filtered by vendor Telerik Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-13661 1 Telerik 1 Fiddler 2020-11-13 6.8 MEDIUM 8.8 HIGH
Telerik Fiddler through 5.0.20202.18177 allows attackers to execute arbitrary programs via a hostname with a trailing space character, followed by --utility-and-browser --utility-cmd-prefix= and the pathname of a locally installed program. The victim must interactively choose the Open On Browser option. Fixed in version 5.0.20204.
CVE-2020-11414 1 Telerik 1 Ui For Silverlight 2020-04-02 5.0 MEDIUM 7.5 HIGH
An issue was discovered in Progress Telerik UI for Silverlight before 2020.1.330. The RadUploadHandler class in RadUpload for Silverlight expects a web request that provides the file location of the uploading file along with a few other parameters. The uploading file location should be inside the directory where the upload handler class is defined. Before 2020.1.330, a crafted web request could result in uploads to arbitrary locations.
CVE-2018-15122 1 Telerik 2 Justassembly, Justdecompile 2018-10-15 6.8 MEDIUM 7.8 HIGH
An issue found in Progress Telerik JustAssembly through 2018.1.323.2 and JustDecompile through 2018.2.605.0 makes it possible to execute code by decompiling a compiled .NET object (such as DLL or EXE) with an embedded resource file by clicking on the resource.