Show filters
113 Total Results
Displaying 101-110 of 113
Sort by:
Attacker Value
Unknown

CVE-2017-8387

Disclosure Date: July 05, 2017 (last updated November 26, 2024)
STDU Viewer version 1.6.375 might allow user-assisted attackers to execute code via a crafted file. One threat model is a victim who obtains an untrusted crafted file from a remote location and issues several user-defined commands including Ctrl-+ commands.
0
Attacker Value
Unknown

CVE-2017-2681

Disclosure Date: May 11, 2017 (last updated September 10, 2024)
Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that product. Human interaction is required to recover the system. PROFIBUS interfaces are not affected.
Attacker Value
Unknown

CVE-2017-2680

Disclosure Date: May 11, 2017 (last updated September 10, 2024)
Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interfaces are not affected.
Attacker Value
Unknown

CVE-2014-1677

Disclosure Date: April 03, 2017 (last updated November 26, 2024)
Technicolor TC7200 with firmware STD6.01.12 could allow remote attackers to obtain sensitive information.
0
Attacker Value
Unknown

CVE-2015-1029

Disclosure Date: January 16, 2015 (last updated October 05, 2023)
The puppetlabs-stdlib module 2.1 through 3.0 and 4.1.0 through 4.5.x before 4.5.1 for Puppet 2.8.8 and earlier allows remote authenticated users to gain privileges or obtain sensitive information by prepopulating the fact cache.
0
Attacker Value
Unknown

CVE-2014-0621

Disclosure Date: January 08, 2014 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Technicolor (formerly Thomson) TC7200 STD6.01.12 allow remote attackers to hijack the authentication of administrators for requests that (1) perform a factory reset via a request to goform/system/factory, (2) disable advanced options via a request to goform/advanced/options, (3) remove ip-filters via the IpFilterAddressDelete1 parameter to goform/advanced/ip-filters, or (4) remove firewall settings via the cbFirewall parameter to goform/advanced/firewall.
0
Attacker Value
Unknown

CVE-2014-0620

Disclosure Date: January 08, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Technicolor (formerly Thomson) TC7200 STD6.01.12 allow remote attackers to inject arbitrary web script or HTML via the (1) ADDNewDomain parameter to parental/website-filters.asp or (2) VmTracerouteHost parameter to goform/status/diagnostics-route.
0
Attacker Value
Unknown

CVE-2010-5221

Disclosure Date: September 06, 2012 (last updated October 05, 2023)
Untrusted search path vulnerability in STDU Explorer 1.0.201 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2010-1959

Disclosure Date: May 27, 2010 (last updated October 04, 2023)
Unspecified vulnerability in HP TestDirector for Quality Center 9.2 before Patch8 allows remote attackers to modify data via unknown vectors.
0
Attacker Value
Unknown

CVE-2007-5289

Disclosure Date: February 24, 2009 (last updated October 04, 2023)
HP Mercury Quality Center (QC) 9.2 and earlier, and possibly TestDirector, relies on cached client-side scripts to implement "workflow" and decisions about the "capability" of a user, which allows remote attackers to execute arbitrary code via crafted use of the Open Test Architecture (OTA) API, as demonstrated by modifying (1) common.tds, (2) defects.tds, (3) manrun.tds, (4) req.tds, (5) testlab.tds, or (6) testplan.tds in %tmp%\TD_80, and then setting the file's properties to read-only.
0