Show filters
55 Total Results
Displaying 21-30 of 55
Sort by:
Attacker Value
Unknown

CVE-2020-4035

Disclosure Date: June 03, 2020 (last updated February 21, 2025)
In WatermelonDB (NPM package "@nozbe/watermelondb") before versions 0.15.1 and 0.16.2, a maliciously crafted record ID can exploit a SQL Injection vulnerability in iOS adapter implementation and cause the app to delete all or selected records from the database, generally causing the app to become unusable. This may happen in apps that don't validate IDs (valid IDs are `/^[a-zA-Z0-9_-.]+$/`) and use Watermelon Sync or low-level `database.adapter.destroyDeletedRecords` method. The integrity risk is low due to the fact that maliciously deleted records won't synchronize, so logout-login will restore all data, although some local changes may be lost if the malicious deletion causes the sync process to fail to proceed to push stage. No way to breach confidentiality with this vulnerability is known. Full exploitation of SQL Injection is mitigated, because it's not possible to nest an insert/update query inside a delete query in SQLite, and it's not possible to pass a semicolon-separated seco…
Attacker Value
Unknown

CVE-2020-5534

Disclosure Date: February 21, 2020 (last updated February 21, 2025)
Aterm WG2600HS firmware Ver1.3.2 and earlier allows an authenticated attacker on the same network segment to execute arbitrary OS commands with root privileges via unspecified vectors.
Attacker Value
Unknown

CVE-2020-5524

Disclosure Date: February 21, 2020 (last updated February 21, 2025)
Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS firmware Ver1.3.2 and earlier) allows an attacker on the same network segment to execute arbitrary OS commands with root privileges via UPnP function.
Attacker Value
Unknown

CVE-2020-5533

Disclosure Date: February 21, 2020 (last updated February 21, 2025)
Cross-site scripting vulnerability in Aterm WG2600HS firmware Ver1.3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Attacker Value
Unknown

CVE-2020-5525

Disclosure Date: February 21, 2020 (last updated February 21, 2025)
Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS firmware Ver1.3.2 and earlier) allows an authenticated attacker on the same network segment to execute arbitrary OS commands with root privileges via management screen.
Attacker Value
Unknown

CVE-2018-0641

Disclosure Date: January 09, 2019 (last updated November 27, 2024)
Buffer overflow in Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary code via tools_system.cgi date parameter, time parameter, and offset parameter.
0
Attacker Value
Unknown

CVE-2018-0628

Disclosure Date: January 09, 2019 (last updated November 27, 2024)
Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via HTTP request and response.
0
Attacker Value
Unknown

CVE-2018-0633

Disclosure Date: January 09, 2019 (last updated November 27, 2024)
Buffer overflow in Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary code via submit-url parameter.
0
Attacker Value
Unknown

CVE-2018-16195

Disclosure Date: January 09, 2019 (last updated November 27, 2024)
Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows an attacker on the same network segment to execute arbitrary OS commands via SOAP interface of UPnP.
0
Attacker Value
Unknown

CVE-2018-16194

Disclosure Date: January 09, 2019 (last updated November 27, 2024)
Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows authenticated attackers to execute arbitrary OS commands via unspecified vectors.
0