Show filters
164 Total Results
Displaying 141-150 of 164
Sort by:
Attacker Value
Unknown

CVE-2013-3686

Disclosure Date: October 11, 2013 (last updated October 05, 2023)
cgi-bin/operator/param in AirLive WL2600CAM and possibly other camera models allows remote attackers to obtain the administrator password via a list action.
0
Attacker Value
Unknown

CVE-2013-3687

Disclosure Date: October 11, 2013 (last updated October 05, 2023)
AirLive POE2600HD, POE250HD, POE200HD, OD-325HD, OD-2025HD, OD-2060HD, POE100HD, and possibly other camera models use cleartext to store sensitive information, which allows attackers to obtain passwords, user names, and other sensitive information by reading an unspecified backup file.
0
Attacker Value
Unknown

CVE-2013-3541

Disclosure Date: October 04, 2013 (last updated October 05, 2023)
Directory traversal vulnerability in cgi-bin/admin/fileread in AirLive WL2600CAM and possibly other camera models allows remote attackers to read arbitrary files via a .. (dot dot) in the READ.filePath parameter.
0
Attacker Value
Unknown

CVE-2013-3540

Disclosure Date: October 04, 2013 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in cgi-bin/admin/usrgrp.cgi in AirLive POE2600HD, POE250HD, POE200HD, OD-325HD, OD-2025HD, OD-2060HD, POE100HD, and possibly other camera models allows remote attackers to hijack the authentication of administrators for requests that add users.
0
Attacker Value
Unknown

CVE-2013-3539

Disclosure Date: October 01, 2013 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T, SNC DH280, and possibly other camera models allows remote attackers to hijack the authentication of administrators for requests that add users.
0
Attacker Value
Unknown

CVE-2013-5323

Disclosure Date: August 20, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Static Info Tables (static_info_tables) extension before 2.3.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-5890

Disclosure Date: November 17, 2012 (last updated October 05, 2023)
The Front End User Registration (sr_feuser_register) extension before 2.6.2 for TYPO3 allows remote attackers to obtain user names and passwords via the (1) edit perspective or (2) autologin feature.
0
Attacker Value
Unknown

CVE-2011-3597

Disclosure Date: January 13, 2012 (last updated October 04, 2023)
Eval injection vulnerability in the Digest module before 1.17 for Perl allows context-dependent attackers to execute arbitrary commands via the new constructor.
0
Attacker Value
Unknown

CVE-2011-0633

Disclosure Date: May 13, 2011 (last updated October 04, 2023)
The Net::HTTPS module in libwww-perl (LWP) before 6.00, as used in WWW::Mechanize, LWP::UserAgent, and other products, when running in environments that do not set the If-SSL-Cert-Subject header, does not enable full validation of SSL certificates by default, which allows remote attackers to spoof servers via man-in-the-middle (MITM) attacks involving hostnames that are not properly validated. NOTE: it could be argued that this is a design limitation of the Net::HTTPS API, and separate implementations should be independently assigned CVE identifiers for not working around this limitation. However, because this API was modified within LWP, a single CVE identifier has been assigned.
0
Attacker Value
Unknown

CVE-2010-2221

Disclosure Date: July 08, 2010 (last updated October 04, 2023)
Multiple buffer overflows in the iSNS implementation in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) before 1.0.6, (2) iSCSI Enterprise Target (aka iscsitarget or IET) 1.4.20.1 and earlier, and (3) Generic SCSI Target Subsystem for Linux (aka SCST or iscsi-scst) 1.0.1.1 and earlier allow remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via (a) a long iSCSI Name string in an SCN message or (b) an invalid PDU.
0