Show filters
51 Total Results
Displaying 31-40 of 51
Sort by:
Attacker Value
Unknown
CVE-2018-18876
Disclosure Date: June 18, 2019 (last updated November 27, 2024)
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a readouts_rd.php directory traversal issue makes it possible to read any file present on the underlying operating system.
0
Attacker Value
Unknown
CVE-2018-18877
Disclosure Date: June 18, 2019 (last updated November 27, 2024)
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can access an alternative configuration page config_main.php that allows manipulation of the device.
0
Attacker Value
Unknown
CVE-2018-18879
Disclosure Date: June 18, 2019 (last updated November 27, 2024)
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the underlying operating system as user input is not sanitized in networkdiags.php.
0
Attacker Value
Unknown
CVE-2018-18880
Disclosure Date: June 18, 2019 (last updated November 27, 2024)
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a networkdiags.php reflected Cross-site scripting (XSS) vulnerability allows remote authenticated users to inject arbitrary web script.
0
Attacker Value
Unknown
CVE-2017-16184
Disclosure Date: June 07, 2018 (last updated November 26, 2024)
scott-blanch-weather-app is a sample Node.js app using Express 4. scott-blanch-weather-app is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
0
Attacker Value
Unknown
CVE-2017-16110
Disclosure Date: June 07, 2018 (last updated November 26, 2024)
weather.swlyons is a simple web server for weather updates. weather.swlyons is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
0
Attacker Value
Unknown
CVE-2017-9245
Disclosure Date: July 19, 2017 (last updated November 26, 2024)
The Google News and Weather application before 3.3.1 for Android allows remote attackers to read OAuth tokens by sniffing the network and leveraging the lack of SSL.
0
Attacker Value
Unknown
CVE-2014-6699
Disclosure Date: September 24, 2014 (last updated October 05, 2023)
The Weather Channel (aka com.weather.Weather) application 5.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-6697
Disclosure Date: September 24, 2014 (last updated October 05, 2023)
The Morocco Weather (aka com.mobilesoft.meteomaroc) application 3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-5981
Disclosure Date: September 20, 2014 (last updated October 05, 2023)
The MoWeather (aka com.moji.moweather) application 1.40.05 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0