Show filters
323 Total Results
Displaying 151-160 of 323
Sort by:
Attacker Value
Unknown
TrackR Bravo mobile application stores account passwords in cleartext
Disclosure Date: July 06, 2018 (last updated November 27, 2024)
The TrackR Bravo mobile app stores the account password used to authenticate to the cloud API in cleartext in the cache.db file. Updated apps, version 5.1.6 for iOS and 2.2.5 for Android, have been released by the vendor to address the vulnerabilities in CVE-2016-6538, CVE-2016-6539, CVE-2016-6540 and CVE-2016-6541.
0
Attacker Value
Unknown
CVE-2018-10689
Disclosure Date: May 03, 2018 (last updated November 08, 2023)
blktrace (aka Block IO Tracing) 1.2.0, as used with the Linux kernel and Android, has a buffer overflow in the dev_map_read function in btt/devmap.c because the device and devno arrays are too small, as demonstrated by an invalid free when using the btt program with a crafted file.
0
Attacker Value
Unknown
DocuTrac DTISQLInstaller.exe Hard-Coded Salt
Disclosure Date: March 19, 2018 (last updated November 26, 2024)
Versions of DocuTrac QuicDoc and Office Therapy that ship with DTISQLInstaller.exe version 1.6.4.0 and prior contains a hard-coded cryptographic salt, "S@l+&pepper".
0
Attacker Value
Unknown
DocuTrac DTISQLInstaller.exe Hard-Coded Credentials
Disclosure Date: March 19, 2018 (last updated November 26, 2024)
Versions of DocuTrac QuicDoc and Office Therapy that ship with DTISQLInstaller.exe version 1.6.4.0 and prior contain three credentials with known passwords: QDMaster, OTMaster, and sa.
0
Attacker Value
Unknown
CVE-2018-6462
Disclosure Date: January 31, 2018 (last updated November 26, 2024)
Tracker PDF-XChange Viewer and Viewer AX SDK before 2.5.322.8 mishandle conversion from YCC to RGB colour spaces by calculating on the basis of 1 bpc instead of 8 bpc, which might allow remote attackers to execute arbitrary code via a crafted PDF document.
0
Attacker Value
Unknown
CVE-2017-18023
Disclosure Date: January 10, 2018 (last updated November 26, 2024)
Office Tracker 11.2.5 has XSS via the logincount parameter to the /otweb/OTPClientLogin URI.
0
Attacker Value
Unknown
CVE-2017-13056
Disclosure Date: December 27, 2017 (last updated November 26, 2024)
The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code via a crafted PDF file.
0
Attacker Value
Unknown
CVE-2017-15968
Disclosure Date: October 29, 2017 (last updated November 26, 2024)
MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter.
0
Attacker Value
Unknown
CVE-2015-2148
Disclosure Date: October 06, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.2 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.
0
Attacker Value
Unknown
CVE-2015-2144
Disclosure Date: October 06, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) project name parameter to project.php; the (2) use_js parameter to user.php; the (3) use_js parameter to group.php; the (4) Description parameter to status.php; the (5) Description parameter to severity.php; the (6) Regex parameter to os.php; or the (7) Name parameter to database.php.
0