Show filters
275 Total Results
Displaying 161-170 of 275
Sort by:
Attacker Value
Unknown

CVE-2019-11016

Disclosure Date: April 08, 2019 (last updated November 27, 2024)
Elgg before 1.12.18 and 2.3.x before 2.3.11 has an open redirect.
0
Attacker Value
Unknown

CVE-2019-8372

Disclosure Date: February 18, 2019 (last updated November 27, 2024)
The LHA.sys driver before 1.1.1811.2101 in LG Device Manager exposes functionality that allows low-privileged users to read and write arbitrary physical memory via specially crafted IOCTL requests and elevate system privileges. This occurs because the device object has an associated symbolic link and an open DACL.
0
Attacker Value
Unknown

CVE-2018-17173

Disclosure Date: September 21, 2018 (last updated November 27, 2024)
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.
0
Attacker Value
Unknown

CVE-2018-17061

Disclosure Date: September 15, 2018 (last updated November 08, 2023)
BullGuard Safe Browsing before 18.1.355.9 allows XSS on Google, Bing, and Yahoo! pages via domains indexed in search results.
0
Attacker Value
Unknown

CVE-2018-16287

Disclosure Date: September 14, 2018 (last updated November 27, 2024)
LG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs.
0
Attacker Value
Unknown

CVE-2018-16286

Disclosure Date: September 14, 2018 (last updated November 27, 2024)
LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is limited to four digits.
0
Attacker Value
Unknown

CVE-2018-16706

Disclosure Date: September 14, 2018 (last updated November 27, 2024)
LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/device/reboot on port 9080.
0
Attacker Value
Unknown

CVE-2018-16288

Disclosure Date: September 14, 2018 (last updated November 27, 2024)
LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs.
0
Attacker Value
Unknown

CVE-2018-16946

Disclosure Date: September 12, 2018 (last updated November 27, 2024)
LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log & Report) files and download backup files (via download.php) without authenticating. These backup files contain user credentials and configuration information for the camera device. An attacker is able to discover the backup filename via reading the system logs or report data, or just by brute-forcing the backup filename pattern. It may be possible to authenticate to the admin account with the admin password.
0
Attacker Value
Unknown

CVE-2018-15138

Disclosure Date: August 15, 2018 (last updated November 27, 2024)
Ericsson-LG iPECS NMS 30M allows directory traversal via ipecs-cm/download?filename=../ URIs.
0