Show filters
194 Total Results
Displaying 131-140 of 194
Sort by:
Attacker Value
Unknown
CVE-2018-7184
Disclosure Date: March 06, 2018 (last updated January 15, 2025)
ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp causing the association to reset and setting the contents of the packet as the most recent timestamp. This issue is a result of an incomplete fix for CVE-2015-7704.
0
Attacker Value
Unknown
CVE-2018-7170
Disclosure Date: March 06, 2018 (last updated January 15, 2025)
ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for CVE-2016-1549.
0
Attacker Value
Unknown
CVE-2014-3205
Disclosure Date: February 23, 2018 (last updated November 26, 2024)
backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user.
0
Attacker Value
Unknown
CVE-2014-3206
Disclosure Date: February 23, 2018 (last updated November 26, 2024)
Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_name parameter to localhost/backupmgmt/pre_connect_check.php.
0
Attacker Value
Unknown
CVE-2014-5334
Disclosure Date: January 08, 2018 (last updated November 26, 2024)
FreeNAS before 9.3-M3 has a blank admin password, which allows remote attackers to gain root privileges by leveraging a WebGui login.
0
Attacker Value
Unknown
CVE-2013-6924
Disclosure Date: October 11, 2017 (last updated November 26, 2024)
Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters in the ip parameter to backupmgt/getAlias.php.
0
Attacker Value
Unknown
CVE-2017-9573
Disclosure Date: June 16, 2017 (last updated November 08, 2023)
The North Adams State Bank (Ursa) nasb-mobile-banking/id980573797 app 3.0.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-8687
Disclosure Date: June 08, 2017 (last updated November 26, 2024)
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use of a static encryption key to create session tokens.
0
Attacker Value
Unknown
CVE-2016-10108
Disclosure Date: January 03, 2017 (last updated November 25, 2024)
Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified arg parameter in the POST data.
0
Attacker Value
Unknown
CVE-2016-10107
Disclosure Date: January 03, 2017 (last updated November 25, 2024)
Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 index.php page via a modified Cookie header.
0