Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown
CVE-2013-5912
Disclosure Date: November 28, 2013 (last updated October 05, 2023)
VhttpdMgr in Thomson Reuters Velocity Analytics Vhayu Analytic Server 6.94 build 2995 allows remote attackers to execute arbitrary code via a URL in the fileName parameter during an importFile action.
0
Attacker Value
Unknown
CVE-2007-6003
Disclosure Date: November 15, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in cgi/b/ic/connect in the Thomson SpeedTouch 716 with firmware 5.4.0.14 allows remote attackers to inject arbitrary web script or HTML via the url parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2007-4753
Disclosure Date: September 08, 2007 (last updated October 04, 2023)
The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) via (1) an empty SIP message or (2) a SIP INVITE message with a malformed To header, different vectors than CVE-2007-4553.
0
Attacker Value
Unknown
CVE-2007-4553
Disclosure Date: August 28, 2007 (last updated October 04, 2023)
The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) via an INVITE message with a Via header that contains a '/' (slash) instead of the required space following the SIP version number.
0
Attacker Value
Unknown
CVE-2006-0947
Disclosure Date: March 01, 2006 (last updated February 22, 2025)
Thomson SpeedTouch modem running firmware 5.3.2.6.0 allows remote attackers to create users that cannot be deleted via scripting code in the "31" parameter in a NewUser function, which is not filtered by the modem when creating the account, but cannot be deleted by the administrator, possibly due to cleansing that occurs in the administrator interface.
0
Attacker Value
Unknown
CVE-2006-0946
Disclosure Date: March 01, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Thomson SpeedTouch modems running firmware 5.3.2.6.0 allows remote attackers to inject arbitrary web script or HTML via the name parameter to the LocalNetwork page.
0
Attacker Value
Unknown
CVE-2005-2440
Disclosure Date: August 03, 2005 (last updated February 22, 2025)
SQL injection vulnerability in login.asp in Thomson Web Skill Vantage Manager allows remote attackers to execute arbitrary SQL commands via the svmPassword parameter.
0
Attacker Value
Unknown
CVE-2005-0494
Disclosure Date: February 21, 2005 (last updated February 22, 2025)
The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly validate the password before performing changes, which allows remote attackers on the LAN to gain access via a direct POST request.
0
Attacker Value
Unknown
CVE-2004-0641
Disclosure Date: August 05, 2004 (last updated February 22, 2025)
Thomson SpeedTouch 510 ADSL Router with firmware GV8BAA3.270, and possibly earlier versions, generates predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.
0