Show filters
49 Total Results
Displaying 21-30 of 49
Sort by:
Attacker Value
Unknown
CVE-2012-0842
Disclosure Date: November 19, 2019 (last updated November 27, 2024)
surf: cookie jar has read access from other local user
0
Attacker Value
Unknown
CVE-2018-3639
Disclosure Date: May 22, 2018 (last updated November 26, 2024)
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.
0
Attacker Value
Unknown
CVE-2015-5993
Disclosure Date: September 21, 2015 (last updated October 05, 2023)
Buffer overflow in form2ping.cgi on Philippine Long Distance Telephone (PLDT) SpeedSurf 504AN devices with firmware GAN9.8U26-4-TX-R6B018-PH.EN and Kasda KW58293 devices allows remote attackers to cause a denial of service (device outage) via a long ipaddr parameter.
0
Attacker Value
Unknown
CVE-2015-5992
Disclosure Date: September 21, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in form2WlanSetup.cgi on Philippine Long Distance Telephone (PLDT) SpeedSurf 504AN devices with firmware GAN9.8U26-4-TX-R6B018-PH.EN and Kasda KW58293 devices allows remote attackers to inject arbitrary web script or HTML via the ssid parameter.
0
Attacker Value
Unknown
CVE-2015-5991
Disclosure Date: September 21, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in form2WlanSetup.cgi on Philippine Long Distance Telephone (PLDT) SpeedSurf 504AN devices with firmware GAN9.8U26-4-TX-R6B018-PH.EN and Kasda KW58293 devices allows remote attackers to hijack the authentication of administrators for requests that perform setup operations, as demonstrated by modifying network settings.
0
Attacker Value
Unknown
CVE-2012-6303
Disclosure Date: October 28, 2013 (last updated October 05, 2023)
Heap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in WaveSurfer 1.8.8p4, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large chunk size in a WAV file.
0
Attacker Value
Unknown
CVE-2011-3626
Disclosure Date: January 27, 2012 (last updated October 04, 2023)
Double free vulnerability in the prepare_exec function in src/exec.c in Logsurfer 1.5b and earlier, and Logsurfer+ 1.7 and earlier, allows remote attackers to execute arbitrary commands via crafted strings in a log file.
0
Attacker Value
Unknown
CVE-2010-2307
Disclosure Date: June 16, 2010 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHPC allow remote attackers to read arbitrary files via (1) "//" (multiple leading slash), (2) ../ (dot dot) sequences, and encoded dot dot sequences in a URL request.
0
Attacker Value
Unknown
CVE-2010-1717
Disclosure Date: May 04, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the iF surfALERT (com_if_surfalert) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
0
Attacker Value
Unknown
CVE-2003-1584
Disclosure Date: February 05, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in SurfStats allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
0