Show filters
247 Total Results
Displaying 121-130 of 247
Sort by:
Attacker Value
Unknown

CVE-2018-0664

Disclosure Date: September 04, 2018 (last updated November 27, 2024)
A vulnerability in NoMachine App for Android 5.0.63 and earlier allows attackers to alter environment variables via unspecified vectors.
0
Attacker Value
Unknown

CVE-2018-10620

Disclosure Date: July 19, 2018 (last updated November 08, 2023)
AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1 a remote user could send a carefully crafted packet to exploit a stack-based buffer overflow vulnerability during tag, alarm, or event related actions such as read and write, with potential for code to be executed.
Attacker Value
Unknown

CVE-2018-7783

Disclosure Date: July 03, 2018 (last updated November 27, 2024)
Schneider Electric SoMachine Basic prior to v1.6 SP1 suffers from an XML External Entity (XXE) vulnerability using the DTD parameter entities technique resulting in disclosure and retrieval of arbitrary data on the affected node via out-of-band (OOB) attack. The vulnerability is triggered when input passed to the xml parser is not sanitized while parsing the xml project/template file.
0
Attacker Value
Unknown

CVE-2018-12290

Disclosure Date: June 13, 2018 (last updated November 26, 2024)
The Yii2-StateMachine extension v2.x.x for Yii2 has XSS.
0
Attacker Value
Unknown

CVE-2018-1235

Disclosure Date: May 29, 2018 (last updated November 26, 2024)
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command injection vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to execute arbitrary commands on the affected system with root privilege.
0
Attacker Value
Unknown

CVE-2018-1242

Disclosure Date: May 29, 2018 (last updated November 26, 2024)
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contains a command injection vulnerability in the Boxmgmt CLI. An authenticated malicious user with boxmgmt privileges may potentially exploit this vulnerability to read RPA files. Note that files that require root permission cannot be read.
0
Attacker Value
Unknown

CVE-2018-1241

Disclosure Date: May 29, 2018 (last updated November 26, 2024)
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, under certain conditions, may leak LDAP password in plain-text into the RecoverPoint log file. An authenticated malicious user with access to the RecoverPoint log files may obtain the exposed LDAP password to use it in further attacks.
0
Attacker Value
Unknown

CVE-2018-10305

Disclosure Date: April 24, 2018 (last updated November 26, 2024)
The MessageSearch2 function in PersonalMessage.php in Simple Machines Forum (SMF) before 2.0.15 does not properly use the possible_users variable in a query, which might allow attackers to bypass intended access restrictions.
0
Attacker Value
Unknown

CVE-2018-8840

Disclosure Date: April 18, 2018 (last updated November 26, 2024)
A remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch Machine Edition 2017 v8.1 and prior versions during a tag, alarm, or event related action such as read and write, which may allow remote code execution.
0
Attacker Value
Unknown

CVE-2017-12701

Disclosure Date: April 17, 2018 (last updated November 26, 2024)
BMC Medical Luna CPAP Machines released prior to July 1, 2017, contain an improper input validation vulnerability which may allow an authenticated attacker to crash the CPAP's Wi-Fi module resulting in a denial-of-service condition.
0