Show filters
155 Total Results
Displaying 131-140 of 155
Sort by:
Attacker Value
Unknown

CVE-2010-2966

Disclosure Date: August 05, 2010 (last updated October 04, 2023)
The INCLUDE_SECURITY functionality in Wind River VxWorks 6.x, 5.x, and earlier uses the LOGIN_USER_NAME and LOGIN_USER_PASSWORD (aka LOGIN_PASSWORD) parameters to create hardcoded credentials, which makes it easier for remote attackers to obtain access via a (1) telnet, (2) rlogin, or (3) FTP session.
0
Attacker Value
Unknown

CVE-2010-2967

Disclosure Date: August 05, 2010 (last updated October 04, 2023)
The loginDefaultEncrypt algorithm in loginLib in Wind River VxWorks before 6.9 does not properly support a large set of distinct possible passwords, which makes it easier for remote attackers to obtain access via a (1) telnet, (2) rlogin, or (3) FTP session.
0
Attacker Value
Unknown

CVE-2010-2965

Disclosure Date: August 05, 2010 (last updated October 04, 2023)
The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with firmware 3.2.6 and 3.6.1 and other products, allows remote attackers to read or modify arbitrary memory locations, perform function calls, or manage tasks via requests to UDP port 17185, a related issue to CVE-2005-3804.
0
Attacker Value
Unknown

CVE-2003-1575

Disclosure Date: January 28, 2010 (last updated October 04, 2023)
VERITAS File System (VxFS) 3.3.3, 3.4, and 3.5 before MP1 Rolling Patch 02 for Sun Solaris 2.5.1 through 9 does not properly implement inheritance of default ACLs in certain circumstances related to the characteristics of a directory inode, which allows local users to bypass intended file permissions by accessing a file on a VxFS filesystem.
0
Attacker Value
Unknown

CVE-2008-7007

Disclosure Date: August 19, 2009 (last updated October 04, 2023)
Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and gain administrative access by setting the (1) admin_name and (2) admin_pass cookie values to 1.
0
Attacker Value
Unknown

CVE-2008-7006

Disclosure Date: August 19, 2009 (last updated October 04, 2023)
Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and download a backup of the database via a direct request to admin/backupdb.php.
0
Attacker Value
Unknown

CVE-2008-5259

Disclosure Date: April 16, 2009 (last updated October 04, 2023)
Integer signedness error in DivX Web Player 1.4.2.7, and possibly earlier versions, allows remote attackers to execute arbitrary code via a DivX file containing a crafted Stream Format (STRF) chunk, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2008-5538

Disclosure Date: December 12, 2008 (last updated October 04, 2023)
Prevx Prevx1 2, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
0
Attacker Value
Unknown

CVE-2008-4452

Disclosure Date: October 06, 2008 (last updated October 04, 2023)
Buffer overflow in Cambridge Computer Corporation vxFtpSrv 2.0.3 allows remote attackers to cause a denial of service (crash and hang) and possibly execute arbitrary code via a long CWD request.
0
Attacker Value
Unknown

CVE-2008-2476

Disclosure Date: October 03, 2008 (last updated October 04, 2023)
The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS before E7.7.1.1, (5) Juniper JUNOS, and (6) Wind River VxWorks 5.x through 6.4 does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity) or read private network traffic via a spoofed message that modifies the Forward Information Base (FIB).
0