Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown
CVE-2019-3831
Disclosure Date: March 25, 2019 (last updated November 27, 2024)
A vulnerability was discovered in vdsm, version 4.19 through 4.30.3 and 4.30.5 through 4.30.8. The systemd_run function exposed to the vdsm system user could be abused to execute arbitrary commands as root.
0
Attacker Value
Unknown
CVE-2018-10908
Disclosure Date: August 09, 2018 (last updated November 27, 2024)
It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By uploading a specially crafted image, an attacker could cause the qemu-img process to consume unbounded amounts of memory of CPU time, causing a denial of service condition that could potentially impact other users of the host.
0
Attacker Value
Unknown
CVE-2018-9248
Disclosure Date: April 04, 2018 (last updated November 26, 2024)
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header.
0
Attacker Value
Unknown
CVE-2018-9249
Disclosure Date: April 04, 2018 (last updated November 26, 2024)
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass by ignoring the parent.location='login.html' JavaScript code in the response to an unauthenticated request.
0
Attacker Value
Unknown
CVE-2014-2378
Disclosure Date: September 05, 2014 (last updated October 05, 2023)
Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not verify the integrity of downloaded updates, which allows remote attackers to execute arbitrary code via a Trojan horse update.
0
Attacker Value
Unknown
CVE-2014-2379
Disclosure Date: September 05, 2014 (last updated October 05, 2023)
Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not use encryption, which allows remote attackers to interfere with traffic control by replaying transmissions on a wireless network.
0
Attacker Value
Unknown
CVE-2013-6026
Disclosure Date: October 19, 2013 (last updated October 05, 2023)
The web interface on D-Link DIR-100, DIR-120, DI-624S, DI-524UP, DI-604S, DI-604UP, DI-604+, and TM-G5240 routers; Planex BRL-04R, BRL-04UR, and BRL-04CW routers; and Alpha Networks routers allows remote attackers to bypass authentication and modify settings via an xmlset_roodkcableoj28840ybtide User-Agent HTTP header, as exploited in the wild in October 2013.
0
Attacker Value
Unknown
CVE-2007-4477
Disclosure Date: August 22, 2007 (last updated October 04, 2023)
The administration interface in the Planet VC-200M VDSL2 router allows remote attackers to cause a denial of service (administration interface outage) via an HTTP request without a Host header.
0