Show filters
61 Total Results
Displaying 31-40 of 61
Sort by:
Attacker Value
Unknown
CVE-2019-14951
Disclosure Date: August 12, 2019 (last updated November 27, 2024)
The Telenav Scout GPS Link app 1.x for iOS, as used with Toyota and Lexus vehicles, has an incorrect protection mechanism against brute-force attacks on the authentication process, which makes it easier for attackers to obtain multimedia-screen access via port 7050 on the cellular network, as demonstrated by a DrivingRestriction method call to uma/jsonrpc/mobile.
0
Attacker Value
Unknown
CVE-2018-10566
Disclosure Date: May 02, 2018 (last updated November 26, 2024)
XSS exists in Flexense DupScout Enterprise from v10.0.18 to v10.7.
0
Attacker Value
Unknown
CVE-2017-13696
Disclosure Date: January 24, 2018 (last updated November 26, 2024)
A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9.9.14, Sync Breeze Enterprise 9.9.16, and Disk Pulse Enterprise 9.9.16 where an attacker can craft a malicious GET request and exploit the web server component. Successful exploitation of the software will allow an attacker to gain complete access to the system with NT AUTHORITY / SYSTEM level privileges. The vulnerability lies due to improper handling and sanitization of the incoming request.
0
Attacker Value
Unknown
CVE-2015-1594
Disclosure Date: March 07, 2015 (last updated October 05, 2023)
Untrusted search path vulnerability in Siemens SIMATIC ProSave before 13 SP1; SIMATIC CFC before 8.0 SP4 Upd9 and 8.1 before Upd1; SIMATIC STEP 7 before 5.5 SP1 HF2, 5.5 SP2 before HF7, 5.5 SP3, and 5.5 SP4 before HF4; SIMOTION Scout before 4.4; and STARTER before 4.4 HF3 allows local users to gain privileges via a Trojan horse application file.
0
Attacker Value
Unknown
CVE-2014-5694
Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The Scoutmob local deals & events (aka com.scoutmob.ile) application 3.0.18 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2011-1384
Disclosure Date: January 04, 2012 (last updated October 04, 2023)
The (1) bin/invscoutClient_VPD_Survey and (2) sbin/invscout_lsvpd programs in invscout.rte before 2.2.0.19 on IBM AIX 7.1, 6.1, 5.3, and earlier allow local users to delete arbitrary files, or trigger inventory scout operations on arbitrary files, via a symlink attack on an unspecified file.
0
Attacker Value
Unknown
CVE-2010-5059
Disclosure Date: November 23, 2011 (last updated October 04, 2023)
SQL injection vulnerability in index.php in CMScout 2.0.8 allows remote attackers to execute arbitrary SQL commands via the album parameter in a photos action.
0
Attacker Value
Unknown
CVE-2010-2154
Disclosure Date: June 03, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Search Site in CMScout 2.09, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2008-6725
Disclosure Date: April 17, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in CMScout 2.06 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) index.php in a mythings page (mythings.php) and (2) the users page in admin.php.
0
Attacker Value
Unknown
CVE-2008-6726
Disclosure Date: April 17, 2009 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in CMScout 2.06, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the bit parameter to (1) admin.php and (2) index.php, different vectors than CVE-2008-3415.
0