Show filters
386 Total Results
Displaying 121-130 of 386
Sort by:
Attacker Value
Unknown
CVE-2020-12069
Disclosure Date: December 26, 2022 (last updated February 24, 2025)
In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.
0
Attacker Value
Unknown
CVE-2022-37018
Disclosure Date: December 12, 2022 (last updated October 08, 2023)
A potential vulnerability has been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerability.
0
Attacker Value
Unknown
CVE-2021-3661
Disclosure Date: December 12, 2022 (last updated October 08, 2023)
A potential security vulnerability has been identified in certain HP Workstation BIOS (UEFI firmware) which may allow arbitrary code execution. HP is releasing firmware mitigations for the potential vulnerability.
0
Attacker Value
Unknown
CVE-2022-20968
Disclosure Date: December 12, 2022 (last updated February 24, 2025)
A vulnerability in the Cisco Discovery Protocol processing feature of Cisco IP Phone 7800 and 8800 Series firmware could allow an unauthenticated, adjacent attacker to cause a stack overflow on an affected device.
This vulnerability is due to insufficient input validation of received Cisco Discovery Protocol packets. An attacker could exploit this vulnerability by sending crafted Cisco Discovery Protocol traffic to an affected device. A successful exploit could allow the attacker to cause a stack overflow, resulting in possible remote code execution or a denial of service (DoS) condition on an affected device.
0
Attacker Value
Unknown
CVE-2022-40204
Disclosure Date: December 01, 2022 (last updated February 24, 2025)
A cross-site scripting (XSS) vulnerability exists in all current versions of Digital Alert Systems DASDEC software via the Host Header in undisclosed pages after login.
0
Attacker Value
Unknown
CVE-2019-18265
Disclosure Date: November 30, 2022 (last updated February 24, 2025)
Digital Alert Systems’ DASDEC software prior to version 4.1 contains a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via the SSH username, username field of the login page, or via the HTTP host header. The injected content is stored in logs and rendered when viewed in the web application.
0
Attacker Value
Unknown
CVE-2022-40304
Disclosure Date: November 23, 2022 (last updated February 24, 2025)
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.
0
Attacker Value
Unknown
CVE-2022-40303
Disclosure Date: November 23, 2022 (last updated February 24, 2025)
An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault.
0
Attacker Value
Unknown
CVE-2022-30694
Disclosure Date: November 08, 2022 (last updated February 24, 2025)
The login endpoint /FormLogin in affected web services does not apply proper origin checking.
This could allow authenticated remote attackers to track the activities of other users via a login cross-site request forgery attack.
0
Attacker Value
Unknown
CVE-2020-9285
Disclosure Date: October 20, 2022 (last updated October 08, 2023)
Some versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware that can be attached to the Mini-PCI Express slot on the motherboard that hosts the WiFi card on the device.
0