Show filters
194 Total Results
Displaying 171-180 of 194
Sort by:
Attacker Value
Unknown
CVE-2009-4869
Disclosure Date: May 11, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Nasim Guest Book 1.2 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
0
Attacker Value
Unknown
CVE-2009-4753
Disclosure Date: March 29, 2010 (last updated October 04, 2023)
Multiple buffer overflows in the FTP server on the Addonics NAS Adapter NASU2FW41 with loader 1.17 allow remote attackers to cause a denial of service (TCP/IP outage) via long arguments to the (1) XRMD, (2) delete, (3) RNFR, or (4) RNTO command.
0
Attacker Value
Unknown
CVE-2009-3279
Disclosure Date: September 21, 2009 (last updated October 04, 2023)
The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create a LUKS partition by using the AES-256 cipher in plain CBC mode, which allows local users to obtain sensitive information via a watermark attack.
0
Attacker Value
Unknown
CVE-2009-3200
Disclosure Date: September 21, 2009 (last updated October 04, 2023)
The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create an undocumented recovery key and store it in the ENCK variable in flash memory, which allows local users to bypass the passphrase requirement and decrypt the hard drive by reading this variable, deobfuscating the key, and running a cryptsetup luksOpen command.
0
Attacker Value
Unknown
CVE-2009-3005
Disclosure Date: August 28, 2009 (last updated October 04, 2023)
Lunascape 5.1.3 and 5.1.4 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which triggers a spoofed login form for the site containing that page. NOTE: a related attack was reported in which an arbitrary file: URL is shown.
0
Attacker Value
Unknown
CVE-2008-7081
Disclosure Date: August 25, 2009 (last updated October 04, 2023)
userHandler.cgi in RaidSonic ICY BOX NAS firmware 2.3.2.IB.2.RS.1 allows remote attackers to bypass authentication and gain administrator privileges by setting the login parameter to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2009-2738
Disclosure Date: August 11, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in the WebGUI in FreeNAS before 0.7RC1 allows remote attackers to hijack the authentication of users for unspecified requests via unknown vectors.
0
Attacker Value
Unknown
CVE-2009-2739
Disclosure Date: August 11, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in FreeNAS before 0.69.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
0
Attacker Value
Unknown
CVE-2009-1040
Disclosure Date: March 20, 2009 (last updated October 04, 2023)
Buffer overflow in WinAsm Studio 5.1.5.0 allows user-assisted remote attackers to execute arbitrary code via a crafted project (.wap) file.
0
Attacker Value
Unknown
CVE-2008-6257
Disclosure Date: February 24, 2009 (last updated October 04, 2023)
SQL injection vulnerability in default.asp in Openasp 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idpage parameter in the pages module.
0