Show filters
57 Total Results
Displaying 21-30 of 57
Sort by:
Attacker Value
Unknown

CVE-2021-36123

Disclosure Date: July 13, 2021 (last updated February 23, 2025)
An issue was discovered in Echo ShareCare 8.15.5. The TextReader feature in General/TextReader/TextReader.cfm is susceptible to a local file inclusion vulnerability when processing remote input in the textFile parameter from an authenticated user, leading to the ability to read arbitrary files on the server filesystems as well any files accessible via Universal Naming Convention (UNC) paths.
Attacker Value
Unknown

CVE-2021-36121

Disclosure Date: July 13, 2021 (last updated February 23, 2025)
An issue was discovered in Echo ShareCare 8.15.5. The file-upload feature in Access/DownloadFeed_Mnt/FileUpload_Upd.cfm is susceptible to an unrestricted upload vulnerability via the name1 parameter, when processing remote input from an authenticated user, leading to the ability for arbitrary files to be written to arbitrary filesystem locations via ../ Directory Traversal on the Z: drive (a hard-coded drive letter where ShareCare application files reside) and remote code execution as the ShareCare service user (NT AUTHORITY\SYSTEM).
Attacker Value
Unknown

CVE-2021-36122

Disclosure Date: July 13, 2021 (last updated February 23, 2025)
An issue was discovered in Echo ShareCare 8.15.5. The UnzipFile feature in Access/EligFeedParse_Sup/UnzipFile_Upd.cfm is susceptible to a command argument injection vulnerability when processing remote input in the zippass parameter from an authenticated user, leading to the ability to inject arbitrary arguments to 7z.exe.
Attacker Value
Unknown

CVE-2021-36124

Disclosure Date: July 13, 2021 (last updated February 23, 2025)
An issue was discovered in Echo ShareCare 8.15.5. It does not perform authentication or authorization checks when accessing a subset of sensitive resources, leading to the ability for unauthenticated users to access pages that are vulnerable to attacks such as SQL injection.
Attacker Value
Unknown

CVE-2021-29061

Disclosure Date: June 21, 2021 (last updated February 22, 2025)
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Vfsjfilechooser2 version 0.2.9 and below which occurs when the application attempts to validate crafted URIs.
Attacker Value
Unknown

CVE-2020-14034

Disclosure Date: June 15, 2020 (last updated February 21, 2025)
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_get_codec_from_pt in utils.c has a Buffer Overflow via long value in an SDP Offer packet.
Attacker Value
Unknown

CVE-2020-14033

Disclosure Date: June 15, 2020 (last updated February 21, 2025)
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_streaming_rtsp_parse_sdp in plugins/janus_streaming.c has a Buffer Overflow via a crafted RTSP server.
Attacker Value
Unknown

CVE-2020-13900

Disclosure Date: June 10, 2020 (last updated February 21, 2025)
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_preparse in sdp.c has a NULL pointer dereference.
Attacker Value
Unknown

CVE-2020-13898

Disclosure Date: June 10, 2020 (last updated February 21, 2025)
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_process in sdp.c has a NULL pointer dereference.
Attacker Value
Unknown

CVE-2020-13899

Disclosure Date: June 10, 2020 (last updated February 21, 2025)
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_process_incoming_request in janus.c discloses information from uninitialized stack memory.