Show filters
247 Total Results
Displaying 101-110 of 247
Sort by:
Attacker Value
Unknown
CVE-2019-6543
Disclosure Date: February 13, 2019 (last updated November 27, 2024)
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. Code is executed under the program runtime privileges, which could lead to the compromise of the machine.
0
Attacker Value
Unknown
CVE-2018-20029
Disclosure Date: December 10, 2018 (last updated November 27, 2024)
The nxfs.sys driver in the DokanFS library 0.6.0 in NoMachine before 6.4.6 on Windows 10 allows local users to cause a denial of service (BSOD) because uninitialized memory can be read.
0
Attacker Value
Unknown
Dell EMC RecoverPoint Information Disclosure Vulnerability
Disclosure Date: November 13, 2018 (last updated November 27, 2024)
Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an information disclosure vulnerability. A malicious boxmgmt user may potentially be able to determine the existence of any system file via Boxmgmt CLI.
0
Attacker Value
Unknown
Dell EMC RecoverPoint Uncontrolled Resource Consumption Vulnerability
Disclosure Date: November 13, 2018 (last updated November 27, 2024)
Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an uncontrolled resource consumption vulnerability. A malicious boxmgmt user may potentially be able to consume large amount of CPU bandwidth to make the system slow or to determine the existence of any system file via Boxmgmt CLI.
0
Attacker Value
Unknown
CVE-2018-7798
Disclosure Date: November 02, 2018 (last updated November 27, 2024)
A Insufficient Verification of Data Authenticity (CWE-345) vulnerability exists in the Modicon M221, all versions, which could cause a change of IPv4 configuration (IP address, mask and gateway) when remotely connected to the device.
0
Attacker Value
Unknown
CVE-2018-17916
Disclosure Date: November 02, 2018 (last updated November 27, 2024)
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. A remote attacker could send a carefully crafted packet to exploit a stack-based buffer overflow vulnerability during tag, alarm, or event related actions such as read and write, with potential for code to be executed. If InduSoft Web Studio remote communication security was not enabled, or a password was left blank, a remote user could send a carefully crafted packet to invoke an arbitrary process, with potential for code to be executed. The code would be executed under the privileges of the InduSoft Web Studio or InTouch Edge HMI runtime and could lead to a compromise of the InduSoft Web Studio or InTouch Edge HMI server machine.
0
Attacker Value
Unknown
CVE-2018-17914
Disclosure Date: November 02, 2018 (last updated November 27, 2024)
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability could allow an unauthenticated user to remotely execute code with the same privileges as that of the InduSoft Web Studio or InTouch Edge HMI (formerly InTouch Machine Edition) runtime.
0
Attacker Value
Unknown
CVE-2018-6906
Disclosure Date: November 01, 2018 (last updated November 27, 2024)
A persistent Cross Site Scripting (XSS) vulnerability in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allows an attacker to inject arbitrary JavaScript via the REST API.
0
Attacker Value
Unknown
CVE-2018-6907
Disclosure Date: November 01, 2018 (last updated November 27, 2024)
A Cross Site Request Forgery (CSRF) vulnerability in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allows an attacker to control the RainMachine device via the REST API.
0
Attacker Value
Unknown
CVE-2018-6909
Disclosure Date: November 01, 2018 (last updated November 27, 2024)
A missing X-Frame-Options header in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application could be used by a remote attacker for clickjacking, as demonstrated by triggering an API page request.
0