Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown

CVE-2019-7690

Disclosure Date: May 13, 2019 (last updated November 27, 2024)
In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from process memory for the lifetime of the process, even after the user disconnects from the remote SSH server. This affects Passwordless Authentication that has a Password Protected SSH Private Key.
0
Attacker Value
Unknown

CVE-2019-0542

Disclosure Date: January 09, 2019 (last updated November 08, 2023)
A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerability." This affects xterm.js.
Attacker Value
Unknown

CVE-2017-15376

Disclosure Date: October 16, 2017 (last updated November 26, 2024)
The TELNET service in Mobatek MobaXterm 10.4 does not require authentication, which allows remote attackers to execute arbitrary commands via TCP port 23.
Attacker Value
Unknown

CVE-2016-10369

Disclosure Date: May 08, 2017 (last updated November 08, 2023)
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).
0
Attacker Value
Unknown

CVE-2017-6805

Disclosure Date: March 20, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in the TFTP server in MobaXterm Personal Edition 9.4 allows remote attackers to read arbitrary files via a .. (dot dot) in a GET command.
0
Attacker Value
Unknown

CVE-2015-7244

Disclosure Date: November 04, 2015 (last updated October 05, 2023)
The default configuration of the server in MobaXterm before 8.3 has a disabled Access Control setting and consequently does not require authentication for X11 connections, which allows remote attackers to execute arbitrary commands or obtain sensitive information via X11 packets.
0
Attacker Value
Unknown

CVE-2009-1629

Disclosure Date: May 14, 2009 (last updated October 04, 2023)
ajaxterm.js in AjaxTerm 0.10 and earlier generates session IDs with predictable random numbers based on certain JavaScript functions, which makes it easier for remote attackers to (1) hijack a session or (2) cause a denial of service (session ID exhaustion) via a brute-force attack.
0
Attacker Value
Unknown

CVE-2006-7236

Disclosure Date: January 02, 2009 (last updated October 04, 2023)
The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, which allows user-assisted attackers to execute arbitrary code or have unspecified other impact via escape sequences.
0
Attacker Value
Unknown

CVE-2008-2383

Disclosure Date: January 02, 2009 (last updated October 04, 2023)
CRLF injection vulnerability in xterm allows user-assisted attackers to execute arbitrary commands via LF (aka \n) characters surrounding a command name within a Device Control Request Status String (DECRQSS) escape sequence in a text file, a related issue to CVE-2003-0063 and CVE-2003-0071.
0
Attacker Value
Unknown

CVE-2007-2797

Disclosure Date: August 27, 2007 (last updated October 04, 2023)
xterm, including 192-7.el4 in Red Hat Enterprise Linux and 208-3.1 in Debian GNU/Linux, sets the wrong group ownership of tty devices, which allows local users to write data to other users' terminals.
0