Show filters
29 Total Results
Displaying 21-29 of 29
Sort by:
Attacker Value
Unknown
CVE-2014-6745
Disclosure Date: September 27, 2014 (last updated October 05, 2023)
The Family Location (aka com.sosocome.family) application 3.4 2014-5-20 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-6694
Disclosure Date: September 24, 2014 (last updated October 05, 2023)
The 5SOS Family Planet (aka uk.co.pixelkicks.fivesos) application 2.3.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-5392
Disclosure Date: September 23, 2014 (last updated October 05, 2023)
XML External Entity (XXE) vulnerability in JobScheduler before 1.6.4246 and 7.x before 1.7.4241 allows remote attackers to cause a denial of service and read arbitrary files or directories via a request containing an XML external entity declaration in conjunction with an entity reference.
0
Attacker Value
Unknown
CVE-2014-5393
Disclosure Date: September 11, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.7.x before 1.7.4241 allows remote authenticated users with the info permission to read arbitrary files in the webroot via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-5391
Disclosure Date: September 11, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.7.x before 1.7.4241 allows remote attackers to inject arbitrary web script or HTML via the hash property (location.hash).
0
Attacker Value
Unknown
CVE-2014-3932
Disclosure Date: June 02, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the device registration component in wsf/webservice.php in CoSoSys Endpoint Protector 4 4.3.0.4 and 4.4.0.2 allows remote attackers to execute arbitrary SQL commands via unspecified parameters.
0
Attacker Value
Unknown
CVE-2014-0246
Disclosure Date: May 29, 2014 (last updated October 05, 2023)
SOSreport stores the md5 hash of the GRUB bootloader password in an archive, which allows local users to obtain sensitive information by reading the archive.
0
Attacker Value
Unknown
CVE-2012-2994
Disclosure Date: September 18, 2012 (last updated October 05, 2023)
The CoSoSys Endpoint Protector 4 appliance establishes an EPProot password based entirely on the appliance serial number, which makes it easier for remote attackers to obtain access via a brute-force attack.
0
Attacker Value
Unknown
CVE-2008-7309
Disclosure Date: April 05, 2012 (last updated October 04, 2023)
Insoshi before 20080920 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the ForumPost user_id value via a modified URL, related to a "mass assignment" vulnerability.
0