Show filters
275 Total Results
Displaying 161-170 of 275
Sort by:
Attacker Value
Unknown
CVE-2019-11016
Disclosure Date: April 08, 2019 (last updated November 27, 2024)
Elgg before 1.12.18 and 2.3.x before 2.3.11 has an open redirect.
0
Attacker Value
Unknown
CVE-2019-8372
Disclosure Date: February 18, 2019 (last updated November 27, 2024)
The LHA.sys driver before 1.1.1811.2101 in LG Device Manager exposes functionality that allows low-privileged users to read and write arbitrary physical memory via specially crafted IOCTL requests and elevate system privileges. This occurs because the device object has an associated symbolic link and an open DACL.
0
Attacker Value
Unknown
CVE-2018-17173
Disclosure Date: September 21, 2018 (last updated November 27, 2024)
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.
0
Attacker Value
Unknown
CVE-2018-17061
Disclosure Date: September 15, 2018 (last updated November 08, 2023)
BullGuard Safe Browsing before 18.1.355.9 allows XSS on Google, Bing, and Yahoo! pages via domains indexed in search results.
0
Attacker Value
Unknown
CVE-2018-16287
Disclosure Date: September 14, 2018 (last updated November 27, 2024)
LG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs.
0
Attacker Value
Unknown
CVE-2018-16286
Disclosure Date: September 14, 2018 (last updated November 27, 2024)
LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is limited to four digits.
0
Attacker Value
Unknown
CVE-2018-16706
Disclosure Date: September 14, 2018 (last updated November 27, 2024)
LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/device/reboot on port 9080.
0
Attacker Value
Unknown
CVE-2018-16288
Disclosure Date: September 14, 2018 (last updated November 27, 2024)
LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs.
0
Attacker Value
Unknown
CVE-2018-16946
Disclosure Date: September 12, 2018 (last updated November 27, 2024)
LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log & Report) files and download backup files (via download.php) without authenticating. These backup files contain user credentials and configuration information for the camera device. An attacker is able to discover the backup filename via reading the system logs or report data, or just by brute-forcing the backup filename pattern. It may be possible to authenticate to the admin account with the admin password.
0
Attacker Value
Unknown
CVE-2018-15138
Disclosure Date: August 15, 2018 (last updated November 27, 2024)
Ericsson-LG iPECS NMS 30M allows directory traversal via ipecs-cm/download?filename=../ URIs.
0