Show filters
924 Total Results
Displaying 111-120 of 924
Sort by:
Attacker Value
Unknown
CVE-2022-4344
Disclosure Date: January 12, 2023 (last updated February 24, 2025)
Memory exhaustion in the Kafka protocol dissector in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of service via packet injection or crafted capture file
0
Attacker Value
Unknown
CVE-2022-4874
Disclosure Date: January 11, 2023 (last updated February 24, 2025)
Authentication bypass in Netcomm router models NF20MESH, NF20, and NL1902 allows an unauthenticated user to access content. In order to serve static content, the application performs a check for the existence of specific characters in the URL (.css, .png etc). If it exists, it performs a "fake login" to give the request an active session to load the file and not redirect to the login page.
0
Attacker Value
Unknown
CVE-2022-4873
Disclosure Date: January 11, 2023 (last updated February 24, 2025)
On Netcomm router models NF20MESH, NF20, and NL1902 a stack based buffer overflow affects the sessionKey parameter. By providing a specific number of bytes, the instruction pointer is able to be overwritten on the stack and crashes the application at a known location.
0
Attacker Value
Unknown
CVE-2019-11851
Disclosure Date: December 26, 2022 (last updated February 24, 2025)
The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allows remote attackers to execute arbitrary code via a buffer overflow.
0
Attacker Value
Unknown
CVE-2019-13988
Disclosure Date: December 26, 2022 (last updated October 08, 2023)
Sierra Wireless MGOS before 3.15.2 and 4.x before 4.3 allows attackers to read log files via a Direct Request (aka Forced Browsing).
0
Attacker Value
Unknown
CVE-2020-11101
Disclosure Date: December 26, 2022 (last updated October 08, 2023)
Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with administrator privileges.
0
Attacker Value
Unknown
CVE-2022-3724
Disclosure Date: December 09, 2022 (last updated February 24, 2025)
Crash in the USB HID protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file on Windows
0
Attacker Value
Unknown
CVE-2022-43673
Disclosure Date: November 18, 2022 (last updated February 24, 2025)
Wire through 3.22.3993 on Windows advertises deletion of sent messages; nonetheless, all messages can be retrieved (for a limited period of time) from the AppData\Roaming\Wire\IndexedDB\https_app.wire.com_0.indexeddb.leveldb database.
0
Attacker Value
Unknown
CVE-2022-40488
Disclosure Date: October 31, 2022 (last updated February 24, 2025)
ProcessWire v3.0.200 was discovered to contain a Cross-Site Request Forgery (CSRF).
0
Attacker Value
Unknown
CVE-2022-40487
Disclosure Date: October 31, 2022 (last updated February 24, 2025)
ProcessWire v3.0.200 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Search Users and Search Pages function. These vulnerabilities allow attackers to execute arbitrary web scripts or HTML via injection of a crafted payload.
0