Vulnerabilities (CVE)

Filtered by vendor Thomsonreuters Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-9141 1 Thomsonreuters 1 Fixed Assets Cs 2014-12-17 7.2 HIGH N/A
The installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which allows local users to execute arbitrary code by modifying this program.
CVE-2013-5912 1 Thomsonreuters 1 Velocity Analytics Vhayu Analytic Server 2013-11-29 10.0 HIGH N/A
VhttpdMgr in Thomson Reuters Velocity Analytics Vhayu Analytic Server 6.94 build 2995 allows remote attackers to execute arbitrary code via a URL in the fileName parameter during an importFile action.