Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown

CVE-2018-8863

Disclosure Date: November 09, 2023 (last updated November 18, 2023)
The HTTP header in Philips EncoreAnywhere contains data an attacker may be able to use to gain sensitive information.
Attacker Value
Unknown

CVE-2021-33790

Disclosure Date: May 31, 2021 (last updated February 22, 2025)
The RebornCore library before 4.7.3 allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObject as part of reborncore.common.network.ExtendedPacketBuffer. An attacker can instantiate any class on the classpath with any data. A class usable for exploitation might or might not be present, depending on what Minecraft modifications are installed.
Attacker Value
Unknown

CVE-2018-18984

Disclosure Date: December 14, 2018 (last updated November 27, 2024)
Medtronic CareLink 2090 Programmer CareLink 9790 Programmer 29901 Encore Programmer, all versions, The affected products do not encrypt or do not sufficiently encrypt the following sensitive information while at rest PII and PHI.
Attacker Value
Unknown

CVE-2014-5127

Disclosure Date: August 29, 2014 (last updated October 05, 2023)
Open redirect vulnerability in Innovative Interfaces Encore Discovery Solution 4.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in an unspecified parameter.
0
Attacker Value
Unknown

CVE-2014-5128

Disclosure Date: August 29, 2014 (last updated October 05, 2023)
Innovative Interfaces Encore Discovery Solution 4.3 places a session token in the URI, which might allow remote attackers to obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown

CVE-2011-0178

Disclosure Date: March 23, 2011 (last updated October 04, 2023)
The FSFindFolder API in CarbonCore in Apple Mac OS X before 10.6.7 provides a world-readable directory in response to a call with the kTemporaryFolderType flag, which allows local users to obtain potentially sensitive information by accessing this directory.
0
Attacker Value
Unknown

CVE-2008-6191

Disclosure Date: February 19, 2009 (last updated October 04, 2023)
Conductor.exe in Intrinsic Swimage Encore before 5.0.1.21 contains a hardcoded password, which might allow local users to decrypt certain .bin files. NOTE: it is not clear whether this issue crosses privilege boundaries.
0
Attacker Value
Unknown

CVE-2009-0475

Disclosure Date: February 11, 2009 (last updated October 04, 2023)
Integer underflow in the Huffman decoding functionality (pvmp3_huffman_parsing.cpp) in OpenCORE 2.0 and earlier allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a crafted MP3 file that triggers heap corruption.
0
Attacker Value
Unknown

CVE-2008-2320

Disclosure Date: August 04, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.4, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a long filename to the file management API.
0
Attacker Value
Unknown

CVE-2006-1117

Disclosure Date: March 09, 2006 (last updated February 22, 2025)
nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine, (7) Time Source Master Clock (TSMC), and possibly other products, contains certain options that were only intended for testing and not production, which might allow remote attackers to obtain information about encryption keys and crack those keys with less effort than brute force.
0