Show filters
74 Total Results
Displaying 31-40 of 74
Sort by:
Attacker Value
Unknown
CVE-2018-0421
Disclosure Date: September 05, 2018 (last updated November 27, 2024)
A vulnerability in TCP connection management in Cisco Prime Access Registrar could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition when the application unexpectedly restarts. The vulnerability is due to incorrect handling of incoming TCP SYN packets to specific listening ports. The improper handling of the TCP SYN packets could cause a system file description to be allocated and not freed. An attacker could exploit this vulnerability by sending a crafted stream of TCP SYN packets to the application. A successful exploit could allow the attacker to cause the application to eventually restart if a file description cannot be obtained.
0
Attacker Value
Unknown
CVE-2018-7780
Disclosure Date: July 03, 2018 (last updated November 27, 2024)
In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, a buffer overflow vulnerability exist in cgi program "set".
0
Attacker Value
Unknown
CVE-2018-7781
Disclosure Date: July 03, 2018 (last updated November 27, 2024)
In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, by sending a specially crafted request an authenticated user can view password in clear text and results in privilege escalation.
0
Attacker Value
Unknown
CVE-2018-7782
Disclosure Date: July 03, 2018 (last updated November 27, 2024)
In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, authenticated users can view passwords in clear text.
0
Attacker Value
Unknown
CVE-2018-8817
Disclosure Date: March 25, 2018 (last updated November 08, 2023)
Wampserver before 3.1.3 has CSRF in add_vhost.php.
0
Attacker Value
Unknown
CVE-2018-8732
Disclosure Date: March 19, 2018 (last updated November 08, 2023)
Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the virtual_del parameter.
0
Attacker Value
Unknown
CVE-2018-7228
Disclosure Date: March 09, 2018 (last updated November 26, 2024)
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticated, remote attacker to bypass authentication and get the administrator privileges.
0
Attacker Value
Unknown
CVE-2018-7235
Disclosure Date: March 09, 2018 (last updated November 26, 2024)
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow arbitrary system file download due to lack of validation of the shell meta characters with the value of 'system.download.sd_file'
0
Attacker Value
Unknown
CVE-2018-7227
Disclosure Date: March 09, 2018 (last updated November 26, 2024)
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow retrieving of specially crafted URLs without authentication that can reveal sensitive information to an attacker.
0
Attacker Value
Unknown
CVE-2018-7234
Disclosure Date: March 09, 2018 (last updated November 26, 2024)
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow arbitrary system file download due to lack of validation of SSL certificate.
0