Vulnerabilities > Datev

DATE CVE VULNERABILITY TITLE RISK
2023-06-22 CVE-2023-33387 Cross-site Scripting vulnerability in Datev EG Personal-Management System Comfort/Comfort Plus 16.1.1
A reflected cross-site scripting (XSS) vulnerability in DATEV eG Personal-Management System Comfort/Comfort Plus v15.1.0 to v16.1.1 P4 allows attackers to steal targeted users' login data by sending a crafted link.
network
low complexity
datev CWE-79
6.1
2012-09-07 CVE-2011-5158 Untrusted Search Path vulnerability in Datev Grundpaket Basis Cd23.20
Multiple untrusted search path vulnerabilities in the DMTGUI2.EXE and DvInesLogFileViewer.Exe components in DATEV Grundpaket Basis CD23.20 allow local users to gain privileges via a Trojan horse (1) DVBSKNLANG101.dll or (2) DvZediTermSrvInfo004.dll file in the current working directory, as demonstrated by a directory that contains a .dmt, .adl, .c02, .dof, or .jrf file.
network
datev CWE-426
critical
9.3
2010-02-26 CVE-2010-0689 Remote Command Execution vulnerability in DateV 'DVBSExeCall.ocx' ActiveX Control
The ExecuteExe method in the DVBSExeCall Control ActiveX control 1.0.0.1 in DVBSExeCall.ocx in DATEV Base System (aka Grundpaket Basis) allows remote attackers to execute arbitrary commands via unspecified vectors.
network
low complexity
datev
critical
10.0
2003-12-31 CVE-2003-1169 Unspecified vulnerability in Datev Nutzungskontrolle 2.1/2.2
DATEV Nutzungskontrolle 2.1 and 2.2 has insecure write permissions for critical registry keys, which allows local users to bypass access restrictions by importing NukoInfo values in certain DATEV keys, which disables Nutzungskontrolle.
local
low complexity
datev
4.6