Show filters
114 Total Results
Displaying 101-110 of 114
Sort by:
Attacker Value
Unknown

CVE-2009-5040

Disclosure Date: January 07, 2011 (last updated October 04, 2023)
CallManager Express (CME) on Cisco IOS before 15.0(1)XA allows remote authenticated users to cause a denial of service (device crash) by using an extension mobility (EM) phone to interact with the menu for SNR number changes, aka Bug ID CSCta63555.
0
Attacker Value
Unknown

CVE-2009-4877

Disclosure Date: May 26, 2010 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in WebGUI before 7.7.14 allow remote attackers to hijack the authentication of users for unspecified requests via unknown vectors.
0
Attacker Value
Unknown

CVE-2010-1065

Disclosure Date: March 23, 2010 (last updated October 04, 2023)
Lebisoft Ziyaretci Defteri 7.4 and 7.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/lebisoft.mdb.
0
Attacker Value
Unknown

CVE-2008-4798

Disclosure Date: October 30, 2008 (last updated October 04, 2023)
The loadModule function in lib/WebGUI/Asset.pm in WebGUI before 7.5.30 (stable) allows remote attackers to execute arbitrary code by uploading a Perl module and accessing it via a crafted URL.
0
Attacker Value
Unknown

CVE-2008-4609

Disclosure Date: October 20, 2008 (last updated October 04, 2023)
The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.
0
Attacker Value
Unknown

CVE-2008-3503

Disclosure Date: August 06, 2008 (last updated October 04, 2023)
RSSFromParent in Plain Black WebGUI before 7.5.13 does not restrict view access to Collaboration System (CS) RSS feeds, which allows remote attackers to obtain sensitive information (CS data).
0
Attacker Value
Unknown

CVE-2008-2077

Disclosure Date: May 05, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Plain Black WebGUI 7.4.34 has unknown impact and attack vectors related to "data form list view."
0
Attacker Value
Unknown

CVE-2008-1142

Disclosure Date: April 07, 2008 (last updated October 04, 2023)
rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that rxvt-unicode, mrxvt, aterm, multi-aterm, and wterm are also affected. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.
0
Attacker Value
Unknown

CVE-2008-0940

Disclosure Date: February 25, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Plain Black WebGUI before 7.4.24 allows remote attackers to inject arbitrary web script or HTML when creating a username, a different vulnerability than CVE-2007-0407.
0
Attacker Value
Unknown

CVE-2007-6487

Disclosure Date: December 20, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Plain Black WebGUI 7.4.0 through 7.4.17 allows remote authenticated users with Secondary Admin privileges to create Admin accounts, a different vulnerability than CVE-2006-0680.
0