Show filters
36 Total Results
Displaying 31-36 of 36
Sort by:
Attacker Value
Unknown

CVE-2019-19865

Disclosure Date: February 21, 2020 (last updated February 21, 2025)
Atos Unify OpenScape UC Application V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows XSS. An attacker could exploit this by convincing an authenticated user to inject arbitrary JavaScript code in the Profile Name field. A browser would execute this stored XSS payload.
Attacker Value
Unknown

CVE-2014-2651

Disclosure Date: January 09, 2020 (last updated February 21, 2025)
Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Workpoint Interface
Attacker Value
Unknown

CVE-2014-2650

Disclosure Date: January 09, 2020 (last updated February 21, 2025)
Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP has an OS command injection vulnerability in the web based management interface
Attacker Value
Unknown

CVE-2011-5043

Disclosure Date: December 30, 2011 (last updated October 04, 2023)
TomatoSoft Free Mp3 Player 1.0 allows remote attackers to cause a denial of service (application crash) via a long string in an MP3 file, possibly a buffer overflow.
0
Attacker Value
Unknown

CVE-2005-0016

Disclosure Date: April 14, 2005 (last updated February 22, 2025)
Buffer overflow in the exported_display function in xatitv in gatos before 0.0.5 allows local users to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2004-0395

Disclosure Date: December 06, 2004 (last updated February 22, 2025)
The xatitv program in the gatos package does not properly drop root privileges when the configuration file does not exist, which allows local users to execute arbitrary commands via shell metacharacters in a system call.
0