Show filters
323 Total Results
Displaying 131-140 of 323
Sort by:
Attacker Value
Unknown

CVE-2019-14465

Disclosure Date: July 31, 2019 (last updated November 27, 2024)
fmt_mtm_load_song in fmt/mtm.c in Schism Tracker 20190722 has a heap-based buffer overflow.
Attacker Value
Unknown

CVE-2019-14262

Disclosure Date: July 25, 2019 (last updated November 08, 2023)
MetadataExtractor 2.1.0 allows stack consumption.
0
Attacker Value
Unknown

CVE-2019-12288

Disclosure Date: May 23, 2019 (last updated November 27, 2024)
An issue was discovered in upgrade_htmls.cgi on VStarcam 100T (C7824WIP) KR75.8.53.20 and 200V (C38S) KR203.18.1.20 devices. The web service, network, and account files can be manipulated through a web UI firmware update without any authentication. The attacker can achieve access to the device through a manipulated web UI firmware update.
Attacker Value
Unknown

CVE-2019-12289

Disclosure Date: May 23, 2019 (last updated November 27, 2024)
An issue was discovered in upgrade_firmware.cgi on VStarcam 100T (C7824WIP) CH-sys-48.53.75.119~123 and 200V (C38S) CH-sys-48.53.203.119~123 devices. A remote command can be executed through a system firmware update without authentication. The attacker can modify the files within the internal firmware or even steal account information by executing a command.
0
Attacker Value
Unknown

CVE-2019-17202

Disclosure Date: April 18, 2019 (last updated February 21, 2025)
FastTrack Admin By Request 6.1.0.0 supports group policies that are supposed to allow only a select range of users to elevate to Administrator privilege at will. If a user does not have direct access to the elevation feature through group policies, they are prompted to enter a PIN code in a challenge-response manner upon attempting to elevate privileges. The challenge's response uses a simple algorithm that can be easily emulated via data (customer ID and device name) available to all users, and thus any user can elevate to Administrator privilege.
Attacker Value
Unknown

CVE-2019-10904

Disclosure Date: April 06, 2019 (last updated November 27, 2024)
Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors.
0
Attacker Value
Unknown

CVE-2019-5748

Disclosure Date: January 09, 2019 (last updated November 27, 2024)
In Traccar Server version 4.2, protocol/SpotProtocolDecoder.java might allow XXE attacks.
0
Attacker Value
Unknown

CVE-2018-1000881

Disclosure Date: December 20, 2018 (last updated November 27, 2024)
Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in ComputedAttributesHandler.java that can result in Remote Command Execution. This attack appear to be exploitable via Remote: web application request by a self-registered user. This vulnerability appears to have been fixed in 4.1 and later.
0
Attacker Value
Unknown

CVE-2018-18584

Disclosure Date: October 23, 2018 (last updated November 27, 2024)
In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write.
Attacker Value
Unknown

CVE-2018-14576

Disclosure Date: August 03, 2018 (last updated November 27, 2024)
The mintTokens function of a smart contract implementation for SunContract, an Ethereum token, has an integer overflow via the _amount variable.