Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown

CVE-2019-14704

Disclosure Date: August 06, 2019 (last updated November 27, 2024)
An SSRF issue was discovered in HTTPD on MicroDigital N-series cameras with firmware through 6400.0.8.5 via FTP commands following a newline character in the uploadfile field.
0
Attacker Value
Unknown

CVE-2019-14709

Disclosure Date: August 06, 2019 (last updated November 27, 2024)
A cleartext password storage issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. The file in question is /usr/local/ipsca/mipsca.db. If a camera is compromised, the attacker can gain access to passwords and abuse them to compromise further systems.
0
Attacker Value
Unknown

CVE-2019-14702

Disclosure Date: August 06, 2019 (last updated November 27, 2024)
An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. SQL injection vulnerabilities exist in 13 forms that are reachable through HTTPD. An attacker can, for example, create an admin account.
0
Attacker Value
Unknown

CVE-2019-14700

Disclosure Date: August 06, 2019 (last updated November 27, 2024)
An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. There is disclosure of the existence of arbitrary files via Path Traversal in HTTPD. This occurs because the filename specified in the TZ parameter is accessed with a substantial delay if that file exists.
0
Attacker Value
Unknown

CVE-2019-14698

Disclosure Date: August 06, 2019 (last updated November 27, 2024)
An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. In a CGI program running under the HTTPD web server, a buffer overflow in the param parameter leads to remote code execution in the context of the nobody account.
0
Attacker Value
Unknown

CVE-2019-14705

Disclosure Date: August 06, 2019 (last updated November 27, 2024)
An Incorrect Access Control issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5 because any valid cookie can be used to make requests as an admin.
0
Attacker Value
Unknown

CVE-2018-17854

Disclosure Date: October 01, 2018 (last updated November 27, 2024)
SIMDComp before 0.1.1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) because it can read (and then discard) extra bytes. NOTE: this issue exists because of an incomplete fix for CVE-2018-17427.
0
Attacker Value
Unknown

CVE-2018-17427

Disclosure Date: October 01, 2018 (last updated November 27, 2024)
SIMDComp before 0.1.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) because it can read (and then discard) extra bytes.
0
Attacker Value
Unknown

CVE-2015-5469

Disclosure Date: May 23, 2017 (last updated November 26, 2024)
Absolute path traversal vulnerability in the MDC YouTube Downloader plugin 2.1.0 for WordPress allows remote attackers to read arbitrary files via a full pathname in the file parameter to includes/download.php.
0
Attacker Value
Unknown

CVE-2016-1409

Disclosure Date: May 29, 2016 (last updated November 25, 2024)
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2.1 through 3.17S, IOS XR 2.0.0 through 5.3.2, and NX-OS allows remote attackers to cause a denial of service (packet-processing outage) via crafted ND messages, aka Bug ID CSCuz66542, as exploited in the wild in May 2016.
0