Show filters
373 Total Results
Displaying 131-140 of 373
Sort by:
Attacker Value
Unknown
CVE-2021-20119
Disclosure Date: November 09, 2021 (last updated February 23, 2025)
The password change utility for the Arris SurfBoard SB8200 can have safety measures bypassed that allow any logged-in user to change the administrator password.
0
Attacker Value
Unknown
CVE-2021-42075
Disclosure Date: November 08, 2021 (last updated February 23, 2025)
An issue was discovered in Barrier before 2.3.4. The barriers component (aka the server-side implementation of Barrier) does not correctly close file descriptors for established TCP connections. An unauthenticated remote attacker can thus cause file descriptor exhaustion in the server process, leading to denial of service.
0
Attacker Value
Unknown
CVE-2021-42073
Disclosure Date: November 08, 2021 (last updated February 23, 2025)
An issue was discovered in Barrier before 2.4.0. An attacker can enter an active session state with the barriers component (aka the server-side implementation of Barrier) simply by supplying a client label that identifies a valid client configuration. This label is "Unnamed" by default but could instead be guessed from hostnames or other publicly available information. In the active session state, an attacker can capture input device events from the server, and also modify the clipboard content on the server.
0
Attacker Value
Unknown
CVE-2021-42072
Disclosure Date: November 08, 2021 (last updated February 23, 2025)
An issue was discovered in Barrier before 2.4.0. The barriers component (aka the server-side implementation of Barrier) does not sufficiently verify the identify of connecting clients. Clients can thus exploit weaknesses in the provided protocol to cause denial-of-service or stage further attacks that could lead to information leaks or integrity corruption.
0
Attacker Value
Unknown
CVE-2021-42076
Disclosure Date: November 08, 2021 (last updated February 23, 2025)
An issue was discovered in Barrier before 2.3.4. An attacker can cause memory exhaustion in the barriers component (aka the server-side implementation of Barrier) and barrierc by sending long TCP messages.
0
Attacker Value
Unknown
CVE-2021-42074
Disclosure Date: November 08, 2021 (last updated February 23, 2025)
An issue was discovered in Barrier before 2.3.4. An unauthenticated attacker can cause a segmentation fault in the barriers component (aka the server-side implementation of Barrier) by quickly opening and closing TCP connections while sending a Hello message for each TCP session.
0
Attacker Value
Unknown
CVE-2021-20120
Disclosure Date: October 21, 2021 (last updated February 23, 2025)
The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery attacks. This means that an attacker could make configuration changes (such as changing the administrative password) without the consent of the user.
0
Attacker Value
Unknown
CVE-2021-39317
Disclosure Date: October 06, 2021 (last updated February 23, 2025)
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the affected products. The complete list of affected products and their versions are below: WordPress Plugin: AccessPress Demo Importer <=1.0.6 WordPress Themes: accesspress-basic <= 3.2.1 accesspress-lite <= 2.92 accesspress-mag <= 2.6.5 accesspress-parallax <= 4.5 accesspress-root <= 2.5 accesspress-store <= 2.4.9 agency-lite <= 1.1.6 arrival <= 1.4.2 bingle <= 1.0.4 bloger <= 1.2.6 brovy <= 1.3 construction-lite <= 1.2.5 doko <= 1.0.27 edict-lite <= 1.1.4 eightlaw-lite <= 2.1.5 eightmedi-lite <= 2.1.8 eight-sec <= 1.1.4 eightstore-lite <= 1.2.5 enlighten <= 1.3.5 fotography <= 2.4.0 opstore <= 1.4.3 parallaxsome <= 1.3.6 punte <= 1.1.2 revolve <= 1.3.1 ripple <= 1.2.0 sakala …
0
Attacker Value
Unknown
CVE-2021-33025
Disclosure Date: August 17, 2021 (last updated February 23, 2025)
xArrow SCADA versions 7.2 and prior permits unvalidated registry keys to be run with application-level privileges.
0
Attacker Value
Unknown
CVE-2021-33021
Disclosure Date: August 17, 2021 (last updated February 23, 2025)
xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘edate’ of the resource xhisalarm.htm, which may allow an unauthorized attacker to execute arbitrary code.
0