Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2024-7029

Disclosure Date: August 02, 2024 (last updated September 18, 2024)
Commands can be injected over the network and executed without authentication.
Attacker Value
Unknown

CVE-2024-42418

Disclosure Date: August 22, 2024 (last updated September 05, 2024)
Avtec Outpost uses a default cryptographic key that can be used to decrypt sensitive information.
Attacker Value
Unknown

CVE-2024-39776

Disclosure Date: August 22, 2024 (last updated September 05, 2024)
Avtec Outpost stores sensitive information in an insecure location without proper access controls in place.
Attacker Value
Unknown

CVE-2023-35072

Disclosure Date: September 05, 2023 (last updated February 25, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Coyav Travel Proagent allows SQL Injection.This issue affects Proagent: before 20230904 .
Attacker Value
Unknown

CVE-2013-4982

Disclosure Date: December 27, 2019 (last updated November 27, 2024)
AVTECH AVN801 DVR has a security bypass via the administration login captcha
Attacker Value
Unknown

CVE-2019-13379

Disclosure Date: July 07, 2019 (last updated November 27, 2024)
On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?action=ResetDefaults&src=RA reset and using the default credentials to get in.
0
Attacker Value
Unknown

CVE-2014-7392

Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Russian Federation Traffic Rules (aka com.russia.pdd) application 1.21 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2013-4980

Disclosure Date: March 03, 2014 (last updated October 05, 2023)
Buffer overflow in the RTSP Packet Handler in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, allows remote attackers to cause a denial of service (device crash) and possibly execute arbitrary code via a long string in the URI in an RTSP SETUP request.
0
Attacker Value
Unknown

CVE-2013-4981

Disclosure Date: March 03, 2014 (last updated October 05, 2023)
Buffer overflow in cgi-bin/user/Config.cgi in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, allows remote attackers to cause a denial of service (device crash) and possibly execute arbitrary code via a long string in the Network.SMTP.Receivers parameter.
0
Attacker Value
Unknown

CVE-2008-3939

Disclosure Date: September 05, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in the web interface in AVTECH PageR Enterprise before 5.0.7 allows remote attackers to read arbitrary files via directory traversal sequences in the URI.
0