Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown
CVE-2019-7690
Disclosure Date: May 13, 2019 (last updated November 27, 2024)
In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from process memory for the lifetime of the process, even after the user disconnects from the remote SSH server. This affects Passwordless Authentication that has a Password Protected SSH Private Key.
0
Attacker Value
Unknown
CVE-2019-0542
Disclosure Date: January 09, 2019 (last updated November 08, 2023)
A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerability." This affects xterm.js.
0
Attacker Value
Unknown
CVE-2017-15376
Disclosure Date: October 16, 2017 (last updated November 26, 2024)
The TELNET service in Mobatek MobaXterm 10.4 does not require authentication, which allows remote attackers to execute arbitrary commands via TCP port 23.
0
Attacker Value
Unknown
CVE-2016-10369
Disclosure Date: May 08, 2017 (last updated November 08, 2023)
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).
0
Attacker Value
Unknown
CVE-2017-6805
Disclosure Date: March 20, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in the TFTP server in MobaXterm Personal Edition 9.4 allows remote attackers to read arbitrary files via a .. (dot dot) in a GET command.
0
Attacker Value
Unknown
CVE-2015-7244
Disclosure Date: November 04, 2015 (last updated October 05, 2023)
The default configuration of the server in MobaXterm before 8.3 has a disabled Access Control setting and consequently does not require authentication for X11 connections, which allows remote attackers to execute arbitrary commands or obtain sensitive information via X11 packets.
0
Attacker Value
Unknown
CVE-2009-1629
Disclosure Date: May 14, 2009 (last updated October 04, 2023)
ajaxterm.js in AjaxTerm 0.10 and earlier generates session IDs with predictable random numbers based on certain JavaScript functions, which makes it easier for remote attackers to (1) hijack a session or (2) cause a denial of service (session ID exhaustion) via a brute-force attack.
0
Attacker Value
Unknown
CVE-2006-7236
Disclosure Date: January 02, 2009 (last updated October 04, 2023)
The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, which allows user-assisted attackers to execute arbitrary code or have unspecified other impact via escape sequences.
0
Attacker Value
Unknown
CVE-2008-2383
Disclosure Date: January 02, 2009 (last updated October 04, 2023)
CRLF injection vulnerability in xterm allows user-assisted attackers to execute arbitrary commands via LF (aka \n) characters surrounding a command name within a Device Control Request Status String (DECRQSS) escape sequence in a text file, a related issue to CVE-2003-0063 and CVE-2003-0071.
0
Attacker Value
Unknown
CVE-2007-2797
Disclosure Date: August 27, 2007 (last updated October 04, 2023)
xterm, including 192-7.el4 in Red Hat Enterprise Linux and 208-3.1 in Debian GNU/Linux, sets the wrong group ownership of tty devices, which allows local users to write data to other users' terminals.
0