Show filters
252 Total Results
Displaying 151-160 of 252
Sort by:
Attacker Value
Unknown

CVE-2020-7495

Disclosure Date: June 16, 2020 (last updated February 21, 2025)
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability during zip file extraction exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause unauthorized write access outside of expected path folder when opening the project file.
Attacker Value
Unknown

CVE-2020-7497

Disclosure Date: June 16, 2020 (last updated February 21, 2025)
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause arbitrary application execution when the computer starts.
Attacker Value
Unknown

CVE-2020-7493

Disclosure Date: June 16, 2020 (last updated February 21, 2025)
A CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause malicious code execution when opening the project file.
Attacker Value
Unknown

CVE-2020-7496

Disclosure Date: June 16, 2020 (last updated February 21, 2025)
A CWE-88: Argument Injection or Modification vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause unauthorized write access when opening the project file.
Attacker Value
Unknown

CVE-2020-7494

Disclosure Date: June 16, 2020 (last updated February 21, 2025)
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause malicious code execution when opening the project file.
Attacker Value
Unknown

CVE-2020-11082

Disclosure Date: May 28, 2020 (last updated February 21, 2025)
In Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1.
Attacker Value
Unknown

CVE-2019-19148

Disclosure Date: March 20, 2020 (last updated February 21, 2025)
Tellabs Optical Line Terminal (OLT) 1150 devices allow Remote Command Execution via the -l option to TELNET or SSH. Tellabs has addressed this issue in the SR30.1 and SR31.1 release on February 18, 2020.
Attacker Value
Unknown

CVE-2019-17596

Disclosure Date: October 24, 2019 (last updated November 08, 2023)
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.
Attacker Value
Unknown

Apache MINA SSLFilter security Issue

Disclosure Date: October 01, 2019 (last updated November 27, 2024)
Handling of the close_notify SSL/TLS message does not lead to a connection closure, leading the server to retain the socket opened and to have the client potentially receive clear text messages afterward. Mitigation: 2.0.20 users should migrate to 2.0.21, 2.1.0 users should migrate to 2.1.1. This issue affects: Apache MINA.
Attacker Value
Unknown

CVE-2019-5958

Disclosure Date: May 17, 2019 (last updated November 27, 2024)
Untrusted search path vulnerability in Electronic reception and examination of application for radio licenses Offline 1.0.9.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
0