Show filters
233 Total Results
Displaying 161-170 of 233
Sort by:
Attacker Value
Unknown
CVE-2018-18975
Disclosure Date: May 06, 2019 (last updated November 27, 2024)
An issue was discovered in the Ascensia Contour NEXT ONE app for iOS before 2019-01-15. An attacker may proxy communications between the app and Ascensia backend servers because of a weak certificate-pinning implementation, leading to disclosure of medical information.
0
Attacker Value
Unknown
CVE-2018-18976
Disclosure Date: May 06, 2019 (last updated November 27, 2024)
An issue was discovered in the Ascensia Contour NEXT ONE application for iOS and Android before 2019-01-15. An attacker may retrieve encrypted medical information of any user of the Ascensia cloud platform by performing Direct Object References with a series of user ID values. (This information can be decrypted through a different vulnerability.)
0
Attacker Value
Unknown
CVE-2018-18978
Disclosure Date: May 06, 2019 (last updated November 27, 2024)
An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically coded encryption key. Extraction of the encryption key is necessary for deciphering communications between this application and the backend server. This, in combination with retrieving any user's encrypted data from the Ascensia cloud through another vulnerability, allows an attacker to obtain and modify any patient's medical information.
0
Attacker Value
Unknown
CVE-2019-6481
Disclosure Date: March 29, 2019 (last updated November 27, 2024)
Abine Blur 7.8.2431 allows remote attackers to conduct "Second-Factor Auth Bypass" attacks by using the "Perform a right-click operation to access a forgotten dev menu to insert user passwords that otherwise would require the user to accept a second-factor request in a mobile app." approach, related to a "Multifactor Auth Bypass, Full Disk Encryption Bypass" issue affecting the Affected Chrome Plugin component.
0
Attacker Value
Unknown
CVE-2018-20639
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has HTML injection via the Search Bar.
0
Attacker Value
Unknown
CVE-2018-20641
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.
0
Attacker Value
Unknown
CVE-2018-20643
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory.
0
Attacker Value
Unknown
CVE-2018-20640
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has stored Cross-Site Scripting (XSS) via the Full Name field.
0
Attacker Value
Unknown
CVE-2018-20642
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 allows remote attackers to cause a denial of service (outage of profile editing) via crafted JavaScript code in the KeySkills field.
0
Attacker Value
Unknown
CVE-2018-20138
Disclosure Date: December 13, 2018 (last updated November 27, 2024)
PHP Scripts Mall Entrepreneur B2B Script 3.0.6 allows Stored XSS via Account Settings fields such as FirstName and LastName, a similar issue to CVE-2018-14541.
0