Show filters
235 Total Results
Displaying 181-190 of 235
Sort by:
Attacker Value
Unknown

CVE-2016-2274

Disclosure Date: February 13, 2017 (last updated November 26, 2024)
An issue was discovered in Adcon Telemetry A850 Telemetry Gateway Base Station. The Web Interface does not neutralize or incorrectly neutralizes user-controllable input before it is placed in the output; this could allow for cross-site scripting.
0
Attacker Value
Unknown

CVE-2017-5136

Disclosure Date: February 05, 2017 (last updated February 15, 2024)
An issue was discovered on SendQuick Entera and Avera devices before 2HF16. The application failed to check the access control of the request which could result in an attacker being able to shutdown the system.
0
Attacker Value
Unknown

CVE-2017-5137

Disclosure Date: February 05, 2017 (last updated February 15, 2024)
An issue was discovered on SendQuick Entera and Avera devices before 2HF16. An attacker could request and download the SMS logs from an unauthenticated perspective.
0
Attacker Value
Unknown

CVE-2016-10098

Disclosure Date: February 05, 2017 (last updated February 15, 2024)
An issue was discovered on SendQuick Entera and Avera devices before 2HF16. Multiple Command Injection vulnerabilities allow attackers to execute arbitrary system commands.
0
Attacker Value
Unknown

CVE-2016-7454

Disclosure Date: December 17, 2016 (last updated November 25, 2024)
CSRF vulnerability on Technicolor TC dpc3941T (formerly Cisco dpc3941T) devices with firmware dpc3941-P20-18-v303r20421733-160413a-CMCST allows an attacker to change the Wi-Fi password, open the remote management interface, or reset the router.
0
Attacker Value
Unknown

CVE-2016-4945

Disclosure Date: June 01, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in vpn/js/gateway_login_form_view.js in Citrix NetScaler Gateway 11.0 before Build 66.11 allows remote attackers to inject arbitrary web script or HTML via the NSC_TMAC cookie.
0
Attacker Value
Unknown

CVE-2016-2333

Disclosure Date: April 25, 2016 (last updated November 25, 2024)
SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 use the same hardcoded encryption key across different customers' installations, which allows attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.
0
Attacker Value
Unknown

CVE-2016-2332

Disclosure Date: April 25, 2016 (last updated November 25, 2024)
flu.cgi in the web interface on SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 allows remote authenticated users to execute arbitrary commands via the 5066 (aka dnsmasq) parameter.
0
Attacker Value
Unknown

CVE-2016-2331

Disclosure Date: April 25, 2016 (last updated November 25, 2024)
The web interface on SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 has a default password, which makes it easier for remote attackers to obtain access via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-1325

Disclosure Date: March 09, 2016 (last updated November 25, 2024)
The administration interface on Cisco DPC3939B and DPC3941 devices allows remote attackers to obtain sensitive information via a crafted HTTP request, aka Bug ID CSCus49506.
0