Show filters
247 Total Results
Displaying 121-130 of 247
Sort by:
Attacker Value
Unknown
CVE-2018-0664
Disclosure Date: September 04, 2018 (last updated November 27, 2024)
A vulnerability in NoMachine App for Android 5.0.63 and earlier allows attackers to alter environment variables via unspecified vectors.
0
Attacker Value
Unknown
CVE-2018-10620
Disclosure Date: July 19, 2018 (last updated November 08, 2023)
AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1 a remote user could send a carefully crafted packet to exploit a stack-based buffer overflow vulnerability during tag, alarm, or event related actions such as read and write, with potential for code to be executed.
0
Attacker Value
Unknown
CVE-2018-7783
Disclosure Date: July 03, 2018 (last updated November 27, 2024)
Schneider Electric SoMachine Basic prior to v1.6 SP1 suffers from an XML External Entity (XXE) vulnerability using the DTD parameter entities technique resulting in disclosure and retrieval of arbitrary data on the affected node via out-of-band (OOB) attack. The vulnerability is triggered when input passed to the xml parser is not sanitized while parsing the xml project/template file.
0
Attacker Value
Unknown
CVE-2018-12290
Disclosure Date: June 13, 2018 (last updated November 26, 2024)
The Yii2-StateMachine extension v2.x.x for Yii2 has XSS.
0
Attacker Value
Unknown
CVE-2018-1235
Disclosure Date: May 29, 2018 (last updated November 26, 2024)
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command injection vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to execute arbitrary commands on the affected system with root privilege.
0
Attacker Value
Unknown
CVE-2018-1242
Disclosure Date: May 29, 2018 (last updated November 26, 2024)
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contains a command injection vulnerability in the Boxmgmt CLI. An authenticated malicious user with boxmgmt privileges may potentially exploit this vulnerability to read RPA files. Note that files that require root permission cannot be read.
0
Attacker Value
Unknown
CVE-2018-1241
Disclosure Date: May 29, 2018 (last updated November 26, 2024)
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, under certain conditions, may leak LDAP password in plain-text into the RecoverPoint log file. An authenticated malicious user with access to the RecoverPoint log files may obtain the exposed LDAP password to use it in further attacks.
0
Attacker Value
Unknown
CVE-2018-10305
Disclosure Date: April 24, 2018 (last updated November 26, 2024)
The MessageSearch2 function in PersonalMessage.php in Simple Machines Forum (SMF) before 2.0.15 does not properly use the possible_users variable in a query, which might allow attackers to bypass intended access restrictions.
0
Attacker Value
Unknown
CVE-2018-8840
Disclosure Date: April 18, 2018 (last updated November 26, 2024)
A remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch Machine Edition 2017 v8.1 and prior versions during a tag, alarm, or event related action such as read and write, which may allow remote code execution.
0
Attacker Value
Unknown
CVE-2017-12701
Disclosure Date: April 17, 2018 (last updated November 26, 2024)
BMC Medical Luna CPAP Machines released prior to July 1, 2017, contain an improper input validation vulnerability which may allow an authenticated attacker to crash the CPAP's Wi-Fi module resulting in a denial-of-service condition.
0