Show filters
53 Total Results
Displaying 1-10 of 53
Sort by:
Attacker Value
Unknown

CVE-2016-1010

Disclosure Date: March 12, 2016 (last updated November 25, 2024)
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0963 and CVE-2016-0993.
Attacker Value
Unknown

CVE-2023-4804

Disclosure Date: November 10, 2023 (last updated November 17, 2023)
An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.
Attacker Value
Unknown

CVE-2021-34577

Disclosure Date: November 09, 2022 (last updated December 22, 2024)
In the Kaden PICOFLUX AiR water meter an adversary can read the values through wireless M-Bus mode 5 with a hardcoded shared key while being adjacent to the device.
Attacker Value
Unknown

CVE-2022-38789

Disclosure Date: September 15, 2022 (last updated October 08, 2023)
An issue was discovered in Airties Smart Wi-Fi before 2020-08-04. It allows attackers to change the main/guest SSID and the PSK to arbitrary values, and map the LAN, because of Insecure Direct Object Reference.
Attacker Value
Unknown

CVE-2022-28620

Disclosure Date: June 24, 2022 (last updated October 07, 2023)
A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX supercomputers versions: Prior to node controller firmware associated with HPE Cray EX liquid cooled blades, and all versions of chassis controller firmware associated with HPE Cray EX liquid cooled cabinets prior to 1.6.27/1.5.33/1.4.27; All Slingshot versions prior to 1.7.2; All versions of node controller firmware associated with HPE Cray EX liquid cooled blades, and all versions of chassis controller firmware associated with HPE Cray EX liquid cooled cabinets prior to 1.6.27/1.5.33/1.4.27. HPE has provided a software update to resolve this vulnerability in HPE Cray Legacy Shasta System Solutions, HPE Slingshot, and HPE Cray EX Supercomputers.
Attacker Value
Unknown

CVE-2022-29945

Disclosure Date: April 29, 2022 (last updated October 07, 2023)
DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical location via the AeroScope protocol.
Attacker Value
Unknown

CVE-2021-34576

Disclosure Date: August 31, 2021 (last updated February 23, 2025)
In Kaden PICOFLUX Air in all known versions an information exposure through observable discrepancy exists. This may give sensitive information (water consumption without distinct values) to third parties.
Attacker Value
Unknown

CVE-2020-8321

Disclosure Date: June 09, 2020 (last updated November 28, 2024)
A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution.
Attacker Value
Unknown

CVE-2013-5637

Disclosure Date: January 07, 2020 (last updated February 21, 2025)
PQI AirCard has persistent XSS
Attacker Value
Unknown

CVE-2019-15356

Disclosure Date: November 14, 2019 (last updated November 27, 2024)
The Lava Flair Z1 Android device with a build fingerprint of LAVA/Z1/Z1:8.1.0/O11019/1536680131:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.