Show filters
194 Total Results
Displaying 111-120 of 194
Sort by:
Attacker Value
Unknown
CVE-2018-12297
Disclosure Date: May 13, 2019 (last updated November 27, 2024)
Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.
0
Attacker Value
Unknown
CVE-2018-12295
Disclosure Date: May 13, 2019 (last updated November 27, 2024)
SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId URL parameter.
0
Attacker Value
Unknown
CVE-2019-10239
Disclosure Date: April 24, 2019 (last updated November 27, 2024)
Robotronic RunAsSpc 3.7.0.0 protects stored credentials insufficiently, which allows locally authenticated attackers (under the same user context) to obtain cleartext credentials of the stored account.
0
Attacker Value
Unknown
CVE-2019-3870
Disclosure Date: April 09, 2019 (last updated January 15, 2025)
A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700, that is owner (root) only access. However in some upgraded installations it will have other permissions, such as 0755, because this was the default before Samba 4.8. Within this directory, files are created with mode 0666, which is world-writable, including a sample krb5.conf, and the list of DNS names and servicePrincipalName values to update.
0
Attacker Value
Unknown
CVE-2019-10631
Disclosure Date: April 09, 2019 (last updated November 27, 2024)
Shell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below allows an authenticated attacker to execute arbitrary code via multiple different requests.
0
Attacker Value
Unknown
CVE-2019-10633
Disclosure Date: April 09, 2019 (last updated November 27, 2024)
An eval injection vulnerability in the Python web server routing on the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to execute arbitrary code via the tjp6jp6y4, simZysh, and ck6fup6 APIs.
0
Attacker Value
Unknown
CVE-2019-10632
Disclosure Date: April 09, 2019 (last updated November 27, 2024)
A directory traversal vulnerability in the file browser component on the Zyxel NAS 326 version 5.21 and below allows a lower privileged user to change the location of any other user's files.
0
Attacker Value
Unknown
CVE-2019-10630
Disclosure Date: April 09, 2019 (last updated November 27, 2024)
A plaintext password vulnerability in the Zyxel NAS 326 through 5.21 allows an elevated privileged user to get the admin password of the device.
0
Attacker Value
Unknown
CVE-2019-10634
Disclosure Date: April 09, 2019 (last updated November 27, 2024)
An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to inject arbitrary JavaScript or HTML via the user, group, and file-share description fields.
0
Attacker Value
Unknown
CVE-2018-1160
Disclosure Date: December 20, 2018 (last updated January 15, 2025)
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.
0