Show filters
320 Total Results
Displaying 131-140 of 320
Sort by:
Attacker Value
Unknown

CVE-2019-6855

Disclosure Date: January 06, 2020 (last updated February 21, 2025)
Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20) , and Modicon M580 (all versions prior to V3.10), which could cause a bypass of the authentication process between EcoStruxure Control Expert and the M340 and M580 controllers.
Attacker Value
Unknown

CVE-2019-9197

Disclosure Date: December 31, 2019 (last updated November 27, 2024)
The com.unity3d.kharma protocol handler in Unity Editor 2018.3 allows remote attackers to execute arbitrary code.
Attacker Value
Unknown

CVE-2012-2148

Disclosure Date: December 06, 2019 (last updated November 27, 2024)
An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies
Attacker Value
Unknown

CVE-2019-15986

Disclosure Date: November 21, 2019 (last updated November 27, 2024)
A vulnerability in the CLI of Cisco Unity Express could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. To exploit this vulnerability, an attacker would need valid administrator credentials. The vulnerability is due to improper input validation for certain CLI commands that are executed on a vulnerable system. An attacker could exploit this vulnerability by logging in to the system and sending crafted CLI commands. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system and elevate privileges to root.
Attacker Value
Unknown

CVE-2019-1915

Disclosure Date: October 02, 2019 (last updated November 27, 2024)
A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition (SME), Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections by the affected software. An attacker could exploit this vulnerability by persuading a targeted user to click a malicious link. A successful exploit could allow the attacker to send arbitrary requests that could change the password of a targeted user. An attacker could then take unauthorized actions on behalf of the targeted user.
Attacker Value
Unknown

CVE-2019-12707

Disclosure Date: October 02, 2019 (last updated November 27, 2024)
A vulnerability in the web-based interface of multiple Cisco Unified Communications products could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of the affected software. The vulnerability is due to insufficient validation of user-supplied input by the web-based interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.
Attacker Value
Unknown

CVE-2019-16104

Disclosure Date: September 08, 2019 (last updated November 27, 2024)
Silver Peak EdgeConnect SD-WAN before 8.1.7.x has reflected XSS via the rest/json/configdb/download/ PATH_INFO.
Attacker Value
Unknown

CVE-2019-16105

Disclosure Date: September 08, 2019 (last updated November 27, 2024)
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows ..%2f directory traversal via a rest/json/configdb/download/ URI.
0
Attacker Value
Unknown

CVE-2019-16103

Disclosure Date: September 08, 2019 (last updated November 27, 2024)
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows privilege escalation (by administrators) from the menu to a root Bash OS shell via the spsshell feature.
0
Attacker Value
Unknown

CVE-2019-16102

Disclosure Date: September 08, 2019 (last updated November 27, 2024)
Silver Peak EdgeConnect SD-WAN before 8.1.7.x has an SNMP service with a public value for rocommunity and trapcommunity.
0