Show filters
666 Total Results
Displaying 171-180 of 666
Sort by:
Attacker Value
Unknown
CVE-2020-9395
Disclosure Date: July 06, 2020 (last updated February 21, 2025)
An issue was discovered on Realtek RTL8195AM, RTL8711AM, RTL8711AF, and RTL8710AF devices before 2.0.6. A stack-based buffer overflow exists in the client code that takes care of WPA2's 4-way-handshake via a malformed EAPOL-Key packet with a long keydata buffer.
0
Attacker Value
Unknown
CVE-2020-12773
Disclosure Date: June 08, 2020 (last updated November 28, 2024)
A security misconfiguration vulnerability exists in the SDK of some Realtek ADSL/PON Modem SoC firmware, which allows attackers using a default password to execute arbitrary commands remotely via the build-in network monitoring tool.
0
Attacker Value
Unknown
CVE-2020-12772
Disclosure Date: May 12, 2020 (last updated February 21, 2025)
An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows. A chat message can include an IMG element with a SRC attribute referencing an external host's IP address. Upon access to this external host, the (NT)LM hashes of the user are sent with the HTTP request. This allows an attacker to collect these hashes, crack them, and potentially compromise the computer. (ROAR can be configured for automatic access. Also, access can occur if the user clicks.)
0
Attacker Value
Unknown
CVE-2019-20525
Disclosure Date: March 19, 2020 (last updated February 21, 2025)
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter.
0
Attacker Value
Unknown
CVE-2019-20526
Disclosure Date: March 19, 2020 (last updated February 21, 2025)
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter.
0
Attacker Value
Unknown
CVE-2019-20527
Disclosure Date: March 19, 2020 (last updated February 21, 2025)
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter.
0
Attacker Value
Unknown
CVE-2019-20528
Disclosure Date: March 18, 2020 (last updated February 21, 2025)
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter.
0
Attacker Value
Unknown
CVE-2020-5530
Disclosure Date: February 18, 2020 (last updated February 21, 2025)
Cross-site request forgery (CSRF) vulnerability in Easy Property Listings versions prior to 3.4 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
0
Attacker Value
Unknown
CVE-2019-11867
Disclosure Date: February 12, 2020 (last updated February 21, 2025)
Realtek NDIS driver rt640x64.sys, file version 10.1.505.2015, fails to do any size checking on an input buffer from user space, which the driver assumes has a size greater than zero bytes. To exploit this vulnerability, an attacker must send an IRP with a system buffer size of 0.
0
Attacker Value
Unknown
CVE-2019-19823
Disclosure Date: January 27, 2020 (last updated February 21, 2025)
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0; Rutek RTK 11N AP through 2019-12-12; Sapido GR297n through 2019-12-12; CIK TELECOM MESH ROUTER through 2019-12-12; KCTVJEJU Wireless AP through 2019-12-12; Fibergate FGN-R2 through 2019-12-12; Hi-Wifi MAX-C300N through 2019-12-12; HCN MAX-C300N through 2019-12-12; T-broad GN-866ac through 2019-12-12; Coship EMTA AP through 2019-12-12; and IO-Data WN-AC1167R through 2019-12-12.
0