Show filters
51 Total Results
Displaying 31-40 of 51
Sort by:
Attacker Value
Unknown

CVE-2018-18876

Disclosure Date: June 18, 2019 (last updated November 27, 2024)
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a readouts_rd.php directory traversal issue makes it possible to read any file present on the underlying operating system.
0
Attacker Value
Unknown

CVE-2018-18877

Disclosure Date: June 18, 2019 (last updated November 27, 2024)
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can access an alternative configuration page config_main.php that allows manipulation of the device.
0
Attacker Value
Unknown

CVE-2018-18879

Disclosure Date: June 18, 2019 (last updated November 27, 2024)
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the underlying operating system as user input is not sanitized in networkdiags.php.
0
Attacker Value
Unknown

CVE-2018-18880

Disclosure Date: June 18, 2019 (last updated November 27, 2024)
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a networkdiags.php reflected Cross-site scripting (XSS) vulnerability allows remote authenticated users to inject arbitrary web script.
0
Attacker Value
Unknown

CVE-2017-16184

Disclosure Date: June 07, 2018 (last updated November 26, 2024)
scott-blanch-weather-app is a sample Node.js app using Express 4. scott-blanch-weather-app is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
0
Attacker Value
Unknown

CVE-2017-16110

Disclosure Date: June 07, 2018 (last updated November 26, 2024)
weather.swlyons is a simple web server for weather updates. weather.swlyons is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
0
Attacker Value
Unknown

CVE-2017-9245

Disclosure Date: July 19, 2017 (last updated November 26, 2024)
The Google News and Weather application before 3.3.1 for Android allows remote attackers to read OAuth tokens by sniffing the network and leveraging the lack of SSL.
0
Attacker Value
Unknown

CVE-2014-6699

Disclosure Date: September 24, 2014 (last updated October 05, 2023)
The Weather Channel (aka com.weather.Weather) application 5.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-6697

Disclosure Date: September 24, 2014 (last updated October 05, 2023)
The Morocco Weather (aka com.mobilesoft.meteomaroc) application 3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-5981

Disclosure Date: September 20, 2014 (last updated October 05, 2023)
The MoWeather (aka com.moji.moweather) application 1.40.05 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0