Show filters
420 Total Results
Displaying 111-120 of 420
Sort by:
Attacker Value
Unknown

CVE-2023-22618

Disclosure Date: October 04, 2023 (last updated February 25, 2025)
If Security Hardening guide rules are not followed, then Nokia WaveLite products allow a local user to create new users with administrative privileges by manipulating a web request. This affects (for example) WaveLite Metro 200 and Fan, WaveLite Metro 200 OPS and Fans, WaveLite Metro 200 and F2B fans, WaveLite Metro 200 OPS and F2B fans, WaveLite Metro 200 NE and F2B fans, and WaveLite Metro 200 NE OPS and F2B fans.
Attacker Value
Unknown

CVE-2023-42471

Disclosure Date: September 11, 2023 (last updated February 25, 2025)
The wave.ai.browser application through 1.0.35 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. It contains a manifest entry that exports the wave.ai.browser.ui.splash.SplashScreen activity. This activity uses a WebView component to display web content and doesn't adequately validate or sanitize the URI or any extra data passed in the intent by a third party application (with no permissions).
Attacker Value
Unknown

CVE-2015-2202

Disclosure Date: September 05, 2023 (last updated February 25, 2025)
Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the underlying OS.
Attacker Value
Unknown

CVE-2015-2201

Disclosure Date: September 05, 2023 (last updated February 25, 2025)
Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows VisualRF remote OS command execution and file disclosure by administrative users.
Attacker Value
Unknown

CVE-2015-1391

Disclosure Date: September 05, 2023 (last updated February 25, 2025)
Aruba AirWave before 8.0.7 allows bypass of a CSRF protection mechanism.
Attacker Value
Unknown

CVE-2015-1390

Disclosure Date: September 05, 2023 (last updated February 25, 2025)
Aruba AirWave before 8.0.7 allows XSS attacks agsinat an administrator.
Attacker Value
Unknown

CVE-2023-29738

Disclosure Date: May 30, 2023 (last updated October 08, 2023)
An issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause code execution and escalation of Privileges via the database files.
Attacker Value
Unknown

CVE-2023-29737

Disclosure Date: May 30, 2023 (last updated February 25, 2025)
An issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause a denial of service via the database files.
Attacker Value
Unknown

CVE-2022-47522

Disclosure Date: April 15, 2023 (last updated February 24, 2025)
The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to intercept (possibly cleartext) target-destined frames by spoofing a target's MAC address, sending Power Save frames to the access point, and then sending other frames to the access point (such as authentication frames or re-association frames) to remove the target's original security context. This behavior occurs because the specifications do not require an access point to purge its transmit queue before removing a client's pairwise encryption key.
Attacker Value
Unknown

CVE-2023-23296

Disclosure Date: February 23, 2023 (last updated February 24, 2025)
Korenix JetWave 4200 Series 1.3.0 and JetWave 3200 Series 1.6.0 are vulnerable to Denial of Service via /goform/formDefault.