Show filters
57 Total Results
Displaying 21-30 of 57
Sort by:
Attacker Value
Unknown
CVE-2021-36123
Disclosure Date: July 13, 2021 (last updated February 23, 2025)
An issue was discovered in Echo ShareCare 8.15.5. The TextReader feature in General/TextReader/TextReader.cfm is susceptible to a local file inclusion vulnerability when processing remote input in the textFile parameter from an authenticated user, leading to the ability to read arbitrary files on the server filesystems as well any files accessible via Universal Naming Convention (UNC) paths.
0
Attacker Value
Unknown
CVE-2021-36121
Disclosure Date: July 13, 2021 (last updated February 23, 2025)
An issue was discovered in Echo ShareCare 8.15.5. The file-upload feature in Access/DownloadFeed_Mnt/FileUpload_Upd.cfm is susceptible to an unrestricted upload vulnerability via the name1 parameter, when processing remote input from an authenticated user, leading to the ability for arbitrary files to be written to arbitrary filesystem locations via ../ Directory Traversal on the Z: drive (a hard-coded drive letter where ShareCare application files reside) and remote code execution as the ShareCare service user (NT AUTHORITY\SYSTEM).
0
Attacker Value
Unknown
CVE-2021-36122
Disclosure Date: July 13, 2021 (last updated February 23, 2025)
An issue was discovered in Echo ShareCare 8.15.5. The UnzipFile feature in Access/EligFeedParse_Sup/UnzipFile_Upd.cfm is susceptible to a command argument injection vulnerability when processing remote input in the zippass parameter from an authenticated user, leading to the ability to inject arbitrary arguments to 7z.exe.
0
Attacker Value
Unknown
CVE-2021-36124
Disclosure Date: July 13, 2021 (last updated February 23, 2025)
An issue was discovered in Echo ShareCare 8.15.5. It does not perform authentication or authorization checks when accessing a subset of sensitive resources, leading to the ability for unauthenticated users to access pages that are vulnerable to attacks such as SQL injection.
0
Attacker Value
Unknown
CVE-2021-29061
Disclosure Date: June 21, 2021 (last updated February 22, 2025)
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Vfsjfilechooser2 version 0.2.9 and below which occurs when the application attempts to validate crafted URIs.
0
Attacker Value
Unknown
CVE-2020-14034
Disclosure Date: June 15, 2020 (last updated February 21, 2025)
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_get_codec_from_pt in utils.c has a Buffer Overflow via long value in an SDP Offer packet.
0
Attacker Value
Unknown
CVE-2020-14033
Disclosure Date: June 15, 2020 (last updated February 21, 2025)
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_streaming_rtsp_parse_sdp in plugins/janus_streaming.c has a Buffer Overflow via a crafted RTSP server.
0
Attacker Value
Unknown
CVE-2020-13900
Disclosure Date: June 10, 2020 (last updated February 21, 2025)
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_preparse in sdp.c has a NULL pointer dereference.
0
Attacker Value
Unknown
CVE-2020-13898
Disclosure Date: June 10, 2020 (last updated February 21, 2025)
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_process in sdp.c has a NULL pointer dereference.
0
Attacker Value
Unknown
CVE-2020-13899
Disclosure Date: June 10, 2020 (last updated February 21, 2025)
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_process_incoming_request in janus.c discloses information from uninitialized stack memory.
0