Show filters
323 Total Results
Displaying 131-140 of 323
Sort by:
Attacker Value
Unknown
CVE-2019-14465
Disclosure Date: July 31, 2019 (last updated November 27, 2024)
fmt_mtm_load_song in fmt/mtm.c in Schism Tracker 20190722 has a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2019-14262
Disclosure Date: July 25, 2019 (last updated November 08, 2023)
MetadataExtractor 2.1.0 allows stack consumption.
0
Attacker Value
Unknown
CVE-2019-12288
Disclosure Date: May 23, 2019 (last updated November 27, 2024)
An issue was discovered in upgrade_htmls.cgi on VStarcam 100T (C7824WIP) KR75.8.53.20 and 200V (C38S) KR203.18.1.20 devices. The web service, network, and account files can be manipulated through a web UI firmware update without any authentication. The attacker can achieve access to the device through a manipulated web UI firmware update.
0
Attacker Value
Unknown
CVE-2019-12289
Disclosure Date: May 23, 2019 (last updated November 27, 2024)
An issue was discovered in upgrade_firmware.cgi on VStarcam 100T (C7824WIP) CH-sys-48.53.75.119~123 and 200V (C38S) CH-sys-48.53.203.119~123 devices. A remote command can be executed through a system firmware update without authentication. The attacker can modify the files within the internal firmware or even steal account information by executing a command.
0
Attacker Value
Unknown
CVE-2019-17202
Disclosure Date: April 18, 2019 (last updated February 21, 2025)
FastTrack Admin By Request 6.1.0.0 supports group policies that are supposed to allow only a select range of users to elevate to Administrator privilege at will. If a user does not have direct access to the elevation feature through group policies, they are prompted to enter a PIN code in a challenge-response manner upon attempting to elevate privileges. The challenge's response uses a simple algorithm that can be easily emulated via data (customer ID and device name) available to all users, and thus any user can elevate to Administrator privilege.
0
Attacker Value
Unknown
CVE-2019-10904
Disclosure Date: April 06, 2019 (last updated November 27, 2024)
Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors.
0
Attacker Value
Unknown
CVE-2019-5748
Disclosure Date: January 09, 2019 (last updated November 27, 2024)
In Traccar Server version 4.2, protocol/SpotProtocolDecoder.java might allow XXE attacks.
0
Attacker Value
Unknown
CVE-2018-1000881
Disclosure Date: December 20, 2018 (last updated November 27, 2024)
Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in ComputedAttributesHandler.java that can result in Remote Command Execution. This attack appear to be exploitable via Remote: web application request by a self-registered user. This vulnerability appears to have been fixed in 4.1 and later.
0
Attacker Value
Unknown
CVE-2018-18584
Disclosure Date: October 23, 2018 (last updated November 27, 2024)
In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write.
0
Attacker Value
Unknown
CVE-2018-14576
Disclosure Date: August 03, 2018 (last updated November 27, 2024)
The mintTokens function of a smart contract implementation for SunContract, an Ethereum token, has an integer overflow via the _amount variable.
0