Show filters
29 Total Results
Displaying 21-29 of 29
Sort by:
Attacker Value
Unknown

CVE-2020-36127

Disclosure Date: May 07, 2021 (last updated February 22, 2025)
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by an information disclosure vulnerability. Through the PUK signature functionality, an administrator will not have access to the current p12 certificate and password. When accessing this functionality, the administrator has the option to replace the current certificate and it is not possible to view the certificate password (p12) already deployed on the platform. The replacement p12 certificate returns to users in base64 with its password, which can be accessed by non-administrator users.
Attacker Value
Unknown

CVE-2020-28045

Disclosure Date: November 02, 2020 (last updated February 22, 2025)
An unsigned-library issue was discovered in ProlinOS through 2.4.161.8859R. This OS requires installed applications and all system binaries to be signed either by the manufacturer or by the Point Of Sale application developer and distributor. The signature is a 2048-byte RSA signature verified in the kernel prior to ELF execution. Shared libraries, however, do not need to be signed, and they are not verified. An attacker may execute a custom binary by compiling it as a shared object and loading it via LD_PRELOAD.
Attacker Value
Unknown

CVE-2020-28046

Disclosure Date: November 02, 2020 (last updated February 22, 2025)
An issue was discovered in ProlinOS through 2.4.161.8859R. An attacker with local code execution privileges as a normal user (MAINAPP) can escalate to root privileges by exploiting the setuid installation of the xtables-multi binary and leveraging the ip6tables --modprobe switch.
Attacker Value
Unknown

CVE-2020-28044

Disclosure Date: November 02, 2020 (last updated February 22, 2025)
An attacker with physical access to a PAX Point Of Sale device with ProlinOS through 2.4.161.8859R can boot it in management mode, enable the XCB service, and then list, read, create, and overwrite files with MAINAPP permissions.
Attacker Value
Unknown

CVE-2015-1193

Disclosure Date: January 21, 2015 (last updated October 05, 2023)
Multiple directory traversal vulnerabilities in pax 1:20140703 allow remote attackers to write to arbitrary files via a (1) full pathname or (2) .. (dot dot) in an archive.
0
Attacker Value
Unknown

CVE-2015-1194

Disclosure Date: January 21, 2015 (last updated October 05, 2023)
pax 1:20140703 allows remote attackers to write to arbitrary files via a symlink attack in an archive.
0
Attacker Value
Unknown

CVE-2008-0801

Disclosure Date: February 15, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the PAXXGallery (com_paxxgallery) 0.2 component for Mambo and Joomla! allow remote attackers to execute arbitrary SQL commands via (1) the iid parameter in a view action, and possibly (2) the userid parameter.
0
Attacker Value
Unknown

CVE-2005-0666

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Unknown vulnerability in PaX from the September 2003 release to 2.2 before 2005.03.05, related to SEGMEXEC or RANDEXEC and VMA mirroring, allows local users and possibly remote attackers to bypass intended access restrictions and execute arbitrary code.
0
Attacker Value
Unknown

CVE-2004-1983

Disclosure Date: May 02, 2004 (last updated February 22, 2025)
The arch_get_unmapped_area function in mmap.c in the PaX patches for Linux kernel 2.6, when Address Space Layout Randomization (ASLR) is enabled, allows local users to cause a denial of service (infinite loop) via unknown attack vectors.
0