Show filters
63 Total Results
Displaying 31-40 of 63
Sort by:
Attacker Value
Unknown

CVE-2018-19011

Disclosure Date: January 22, 2019 (last updated November 27, 2024)
CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file. An attacker could exploit this to execute code under the privileges of the application.
0
Attacker Value
Unknown

CVE-2018-19019

Disclosure Date: January 22, 2019 (last updated November 27, 2024)
A type confusion vulnerability exists when processing project files in CX-Supervisor (Versions 3.42 and prior). An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.
0
Attacker Value
Unknown

CVE-2018-17905

Disclosure Date: November 05, 2018 (last updated November 27, 2024)
When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with a specific byte, memory corruption may occur within a specific object.
0
Attacker Value
Unknown

CVE-2018-17913

Disclosure Date: November 05, 2018 (last updated November 27, 2024)
A type confusion vulnerability exists when processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, which may allow an attacker to execute code in the context of the application.
0
Attacker Value
Unknown

CVE-2018-17907

Disclosure Date: November 05, 2018 (last updated November 27, 2024)
When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with the value of an offset, an attacker can force the application to read a value outside of an array.
0
Attacker Value
Unknown

CVE-2018-17909

Disclosure Date: November 05, 2018 (last updated November 27, 2024)
When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, the application fails to check if it is referencing freed memory, which may allow an attacker to execute code under the context of the application.
0
Attacker Value
Unknown

CVE-2018-15404

Disclosure Date: October 03, 2018 (last updated November 27, 2024)
A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient restrictions on the size or total amount of resources allowed via the web interface. An attacker who has valid credentials for the application could exploit this vulnerability by sending a crafted or malformed HTTP request to the web interface. A successful exploit could allow the attacker to cause oversubscription of system resources or cause a component to become unresponsive, resulting in a DoS condition.
0
Attacker Value
Unknown

CMS Supervisor Information Disclosure

Disclosure Date: September 24, 2018 (last updated November 27, 2024)
A vulnerability in the Supervisor component of Avaya Call Management System allows local administrative user to extract sensitive information from users connecting to a remote CMS host. Affected versions of CMS Supervisor include R17.0.x and R18.0.x.
0
Attacker Value
Unknown

CVE-2018-0149

Disclosure Date: June 07, 2018 (last updated November 26, 2024)
A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supervisor Software and Cisco UCS Director Software could allow an authenticated, remote attacker to conduct a Document Object Model-based (DOM-based), stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the affected interface to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or allow the attacker to access sensitive browser-based information on the affected device. Cisco Bug IDs: CSCvh12994.
0
Attacker Value
Unknown

CVE-2018-7525

Disclosure Date: March 21, 2018 (last updated November 26, 2024)
In Omron CX-Supervisor Versions 3.30 and prior, processing a malformed packet by a certain executable may cause an untrusted pointer dereference vulnerability.
0