Ibm Spss Data Collection vulnerabilities
5 known vulnerabilities affecting ibm/spss_data_collection.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2013-0464MEDIUMCVSS 4.3v6.0v6.0.1+1 more2013-06-03
CVE-2013-0464 [MEDIUM] CWE-79 CVE-2013-0464: Multiple cross-site scripting (XSS) vulnerabilities in IBM Eclipse Help System (IEHS) 3.4.3 and 3.6.
Multiple cross-site scripting (XSS) vulnerabilities in IBM Eclipse Help System (IEHS) 3.4.3 and 3.6.2, as used in IBM SPSS Data Collection 6.0, 6.0.1, and 7.0, allow remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2012-2161MEDIUMCVSS 4.3v6.0v6.0.12012-06-20
CVE-2012-2161 [MEDIUM] CWE-79 CVE-2012-2161: Cross-site scripting (XSS) vulnerability in deferredView.jsp in IBM Eclipse Help System (IEHS), as u
Cross-site scripting (XSS) vulnerability in deferredView.jsp in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collection Developer Library 6.0 and 6.0.1, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2012-2159MEDIUMCVSS 5.8v6.0v6.0.12012-06-20
CVE-2012-2159 [MEDIUM] CWE-20 CVE-2012-2159: Open redirect vulnerability in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Sourc
Open redirect vulnerability in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collection Developer Library 6.0 and 6.0.1, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
nvd
CVE-2012-0188CRITICALCVSS 9.3v5.6v6.0+1 more2012-01-18
CVE-2012-0188 [CRITICAL] CVE-2012-0188: Unspecified vulnerability in the SetLicenseInfoEx method in an ActiveX control in mraboutb.dll in IB
Unspecified vulnerability in the SetLicenseInfoEx method in an ActiveX control in mraboutb.dll in IBM SPSS Dimensions 5.5 and SPSS Data Collection 5.6, 6.0, and 6.0.1 allows remote attackers to execute arbitrary code via a crafted HTML document.
nvd
CVE-2012-0190CRITICALCVSS 9.3v5.6v6.0+1 more2012-01-18
CVE-2012-0190 [CRITICAL] CVE-2012-0190: Unspecified vulnerability in the Render method in the ExportHTML.ocx ActiveX control in ExportHTML.d
Unspecified vulnerability in the Render method in the ExportHTML.ocx ActiveX control in ExportHTML.dll in IBM SPSS Dimensions 5.5 and SPSS Data Collection 5.6, 6.0, and 6.0.1 allows remote attackers to execute arbitrary code via a crafted HTML document.
nvd