Show filters
74 Total Results
Displaying 31-40 of 74
Sort by:
Attacker Value
Unknown

CVE-2018-0421

Disclosure Date: September 05, 2018 (last updated November 27, 2024)
A vulnerability in TCP connection management in Cisco Prime Access Registrar could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition when the application unexpectedly restarts. The vulnerability is due to incorrect handling of incoming TCP SYN packets to specific listening ports. The improper handling of the TCP SYN packets could cause a system file description to be allocated and not freed. An attacker could exploit this vulnerability by sending a crafted stream of TCP SYN packets to the application. A successful exploit could allow the attacker to cause the application to eventually restart if a file description cannot be obtained.
0
Attacker Value
Unknown

CVE-2018-7780

Disclosure Date: July 03, 2018 (last updated November 27, 2024)
In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, a buffer overflow vulnerability exist in cgi program "set".
0
Attacker Value
Unknown

CVE-2018-7781

Disclosure Date: July 03, 2018 (last updated November 27, 2024)
In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, by sending a specially crafted request an authenticated user can view password in clear text and results in privilege escalation.
0
Attacker Value
Unknown

CVE-2018-7782

Disclosure Date: July 03, 2018 (last updated November 27, 2024)
In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, authenticated users can view passwords in clear text.
0
Attacker Value
Unknown

CVE-2018-8817

Disclosure Date: March 25, 2018 (last updated November 08, 2023)
Wampserver before 3.1.3 has CSRF in add_vhost.php.
0
Attacker Value
Unknown

CVE-2018-8732

Disclosure Date: March 19, 2018 (last updated November 08, 2023)
Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the virtual_del parameter.
0
Attacker Value
Unknown

CVE-2018-7228

Disclosure Date: March 09, 2018 (last updated November 26, 2024)
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticated, remote attacker to bypass authentication and get the administrator privileges.
Attacker Value
Unknown

CVE-2018-7235

Disclosure Date: March 09, 2018 (last updated November 26, 2024)
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow arbitrary system file download due to lack of validation of the shell meta characters with the value of 'system.download.sd_file'
Attacker Value
Unknown

CVE-2018-7227

Disclosure Date: March 09, 2018 (last updated November 26, 2024)
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow retrieving of specially crafted URLs without authentication that can reveal sensitive information to an attacker.
Attacker Value
Unknown

CVE-2018-7234

Disclosure Date: March 09, 2018 (last updated November 26, 2024)
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow arbitrary system file download due to lack of validation of SSL certificate.