Show filters
20 Total Results
Displaying 11-20 of 20
Sort by:
Attacker Value
Unknown

CVE-2019-9861

Disclosure Date: May 14, 2019 (last updated November 27, 2024)
Due to the use of an insecure RFID technology (MIFARE Classic), ABUS proximity chip keys (RFID tokens) of the ABUS Secvest FUAA50000 wireless alarm system can easily be cloned and used to deactivate the alarm system in an unauthorized way.
0
Attacker Value
Unknown

CVE-2019-9860

Disclosure Date: March 27, 2019 (last updated November 27, 2024)
Due to unencrypted signal communication and predictability of rolling codes, an attacker can "desynchronize" an ABUS Secvest wireless remote control (FUBE50014 or FUBE50015) relative to its controlled Secvest wireless alarm system FUAA50000 3.01.01, so that sent commands by the remote control are not accepted anymore.
0
Attacker Value
Unknown

CVE-2019-9863

Disclosure Date: March 27, 2019 (last updated November 27, 2024)
Due to the use of an insecure algorithm for rolling codes in the ABUS Secvest wireless alarm system FUAA50000 3.01.01 and its remote controls FUBE50014 and FUBE50015, an attacker is able to predict valid future rolling codes, and can thus remotely control the alarm system in an unauthorized way.
0
Attacker Value
Unknown

CVE-2019-9862

Disclosure Date: March 27, 2019 (last updated November 27, 2024)
An issue was discovered on ABUS Secvest wireless alarm system FUAA50000 3.01.01 in conjunction with Secvest remote control FUBE50014 or FUBE50015. Because "encrypted signal transmission" is missing, an attacker is able to eavesdrop sensitive data as cleartext (for instance, the current rolling code state).
0
Attacker Value
Unknown

CVE-2009-4862

Disclosure Date: May 11, 2010 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Alwasel 1.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) show.php and (2) xml.php.
0
Attacker Value
Unknown

CVE-2006-2139

Disclosure Date: May 02, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in PHP Newsfeed 20040723 allow remote attackers to execute arbitrary SQL commands via the (1) name parameter to (a) deltables.php, (2) select, (3) header, (4) url, (5) source, or (6) time parameters to (b) manualsubmit.php, (7) num parameter to (c) delete.php, or (8) tablename parameter to (d) searchnews.php.
0
Attacker Value
Unknown

CVE-2005-0098

Disclosure Date: March 08, 2005 (last updated February 22, 2025)
Multiple buffer overflows in the SDL port of abuse (abuse-SDL) before 2.00 allow local users to execute arbitrary code via the command line.
0
Attacker Value
Unknown

CVE-2005-0099

Disclosure Date: March 08, 2005 (last updated February 22, 2025)
The SDL port of abuse (abuse-SDL) before 2.00 does not properly drop privileges before creating certain files, which allows local users to create or overwrite arbitrary files.
0
Attacker Value
Unknown

CVE-2002-1253

Disclosure Date: November 12, 2002 (last updated February 22, 2025)
Abuse 2.00 and earlier allows local users to gain privileges via command line arguments that specify alternate Lisp scripts that run at escalated privileges, which can contain functions that execute commands or modify files.
0
Attacker Value
Unknown

CVE-2002-1250

Disclosure Date: November 12, 2002 (last updated February 22, 2025)
Buffer overflow in Abuse 2.00 and earlier allows local users to gain root privileges via a long -net command line argument.
0