Show filters
30 Total Results
Displaying 11-20 of 30
Sort by:
Attacker Value
Unknown

CVE-2023-25411

Disclosure Date: April 11, 2023 (last updated October 08, 2023)
Aten PE8108 2.4.232 is vulnerable to Cross Site Request Forgery (CSRF).
Attacker Value
Unknown

CVE-2023-25409

Disclosure Date: April 11, 2023 (last updated October 08, 2023)
Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. Restricted users have access to other users outlets.
Attacker Value
Unknown

CVE-2023-25407

Disclosure Date: April 11, 2023 (last updated October 08, 2023)
Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. Restricted users have read access to administrator credentials.
Attacker Value
Unknown

CVE-2018-10758

Disclosure Date: May 05, 2018 (last updated November 26, 2024)
The edit/ URI in Datenstrom Yellow 0.7.3 has CSRF via a delete action that can delete articles.
0
Attacker Value
Unknown

CVE-2018-10726

Disclosure Date: May 04, 2018 (last updated November 08, 2023)
A stored XSS vulnerability was found in Datenstrom Yellow 0.7.3 via an "Edit page" action. NOTE: the vendor disputes the relevance of this report because an installation accessible to untrusted users is supposed to have parserSafeMode=1 in system/config/config.ini to prevent XSS
0
Attacker Value
Unknown

CVE-2018-0560

Disclosure Date: April 16, 2018 (last updated November 26, 2024)
Hatena Bookmark App for iOS Version 3.0 to 3.70 allows remote attackers to spoof the address bar via vectors related to URL display.
0
Attacker Value
Unknown

CVE-2014-1997

Disclosure Date: June 05, 2014 (last updated October 05, 2023)
The ATEN CN8000 remote-access unit with firmware 1.6.154 and earlier allows remote attackers to cause a denial of service via unspecified vectors.
0
Attacker Value
Unknown

CVE-2011-4701

Disclosure Date: January 25, 2012 (last updated October 04, 2023)
The CallConfirm (jp.gr.java_conf.ofnhwx.callconfirm) application 2.0.0 for Android does not properly protect data, which allows remote attackers to read or modify allow/block lists via a crafted application.
0
Attacker Value
Unknown

CVE-2009-1473

Disclosure Date: May 27, 2009 (last updated October 04, 2023)
The (1) Windows and (2) Java client programs for the ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmware 1.1.104 do not properly use RSA cryptography for a symmetric session-key negotiation, which makes it easier for remote attackers to (a) decrypt network traffic, or (b) conduct man-in-the-middle attacks, by repeating unspecified "client-side calculations."
0
Attacker Value
Unknown

CVE-2009-1472

Disclosure Date: May 27, 2009 (last updated October 04, 2023)
The Java client program for the ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmware 1.1.104 has a hardcoded AES encryption key, which makes it easier for man-in-the-middle attackers to (1) execute arbitrary Java code, or (2) gain access to machines connected to the switch, by hijacking a session.
0