Show filters
301 Total Results
Displaying 191-200 of 301
Sort by:
Attacker Value
Unknown
CVE-2014-2941
Disclosure Date: August 15, 2014 (last updated November 08, 2023)
Cobham Sailor 6000 satellite terminals have hardcoded Tbus 2 credentials, which allows remote attackers to obtain access via a TBUS2 command. NOTE: the vendor reportedly states "there is no possibility to exploit another user's credentials.
0
Attacker Value
Unknown
CVE-2014-0328
Disclosure Date: August 15, 2014 (last updated October 05, 2023)
The thraneLINK protocol implementation on Cobham devices does not verify firmware signatures, which allows attackers to execute arbitrary code by leveraging physical access or terminal access to send an SNMP request and a TFTP response.
0
Attacker Value
Unknown
CVE-2014-4549
Disclosure Date: July 02, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in pages/3DComplete.php in the WooCommerce SagePay Direct Payment Gateway plugin before 0.1.6.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) MD or (2) PARes parameter.
0
Attacker Value
Unknown
CVE-2014-2347
Disclosure Date: May 06, 2014 (last updated October 05, 2023)
Amtelco miSecureMessages (aka MSM) 6.2 does not properly manage sessions, which allows remote authenticated users to obtain sensitive information via a modified message request.
0
Attacker Value
Unknown
CVE-2014-0924
Disclosure Date: April 15, 2014 (last updated October 05, 2023)
IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 does not verify that all of the characters of a password are correct, which makes it easier for remote authenticated users to bypass intended access restrictions by leveraging knowledge of a password substring.
0
Attacker Value
Unknown
CVE-2014-0921
Disclosure Date: April 15, 2014 (last updated October 05, 2023)
The server in IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (daemon crash and message data loss) via malformed headers during a WebSockets connection upgrade.
0
Attacker Value
Unknown
CVE-2014-0922
Disclosure Date: April 15, 2014 (last updated October 05, 2023)
IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (resource consumption) via WebSockets MQ Telemetry Transport (MQTT) data.
0
Attacker Value
Unknown
CVE-2014-0923
Disclosure Date: April 15, 2014 (last updated October 05, 2023)
IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (daemon restart) via crafted MQ Telemetry Transport (MQTT) authentication data.
0
Attacker Value
Unknown
CVE-2014-0357
Disclosure Date: April 15, 2014 (last updated October 05, 2023)
Amtelco miSecureMessages allows remote attackers to read the messages of arbitrary users via an XML request containing a valid license key and a modified contactID value, as demonstrated by a request from the iOS or Android application.
0
Attacker Value
Unknown
CVE-2013-6143
Disclosure Date: January 31, 2014 (last updated October 05, 2023)
The Schneider Electric Telvent SAGE 3030 RTU with firmware C3413-500-001D3_P4 and C3413-500-001F0_PB allows remote attackers to cause a denial of service (temporary outage and CPU consumption) via malformed DNP3 traffic.
0