Show filters
207 Total Results
Displaying 191-200 of 207
Sort by:
Attacker Value
Unknown
CVE-2014-7169
Disclosure Date: September 25, 2014 (last updated July 25, 2024)
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.
0
Attacker Value
Unknown
CVE-2013-5760
Disclosure Date: June 09, 2014 (last updated October 05, 2023)
QNAP Photo Station before firmware 4.0.3 build0912 allows remote attackers to list OS user accounts via a request to photo/p/api/list.php.
0
Attacker Value
Unknown
CVE-2014-3468
Disclosure Date: June 05, 2014 (last updated October 05, 2023)
The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.
0
Attacker Value
Unknown
CVE-2014-3467
Disclosure Date: June 05, 2014 (last updated October 05, 2023)
Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTLS, allow remote attackers to cause a denial of service (out-of-bounds read) via crafted ASN.1 data.
0
Attacker Value
Unknown
CVE-2013-6884
Disclosure Date: January 07, 2014 (last updated October 05, 2023)
The write-blocker in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a has a default "ditto" username and password, which allows remote attackers to gain privileges.
0
Attacker Value
Unknown
CVE-2013-6881
Disclosure Date: January 07, 2014 (last updated October 05, 2023)
CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) sector size or (2) skip count fields for the forensic imaging task.
0
Attacker Value
Unknown
CVE-2013-6882
Disclosure Date: December 17, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in CRU Ditto Forensic FieldStation with firmware 2013Oct15a and earlier allow (1) remote attackers to inject arbitrary web script or HTML via the username parameter in a login or (2) remote authenticated users to inject arbitrary web script or HTML via unspecified form fields.
0
Attacker Value
Unknown
CVE-2013-6883
Disclosure Date: December 17, 2013 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to hijack the authentication of administrators for requests that modify the disk erase technique settings via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-5132
Disclosure Date: September 08, 2013 (last updated October 05, 2023)
Apple AirPort Base Station Firmware before 7.6.4 does not properly handle incorrect frame lengths, which allows remote attackers to cause a denial of service (device crash) by associating with the access point and then sending a short frame.
0
Attacker Value
Unknown
CVE-2013-3435
Disclosure Date: July 23, 2013 (last updated October 05, 2023)
The Cisco Unified IP Conference Station 7937G allows remote attackers to cause a denial of service (networking outage) via a flood of TCP packets, aka Bug ID CSCuh42052.
0