Show filters
60 Total Results
Displaying 31-40 of 60
Sort by:
Attacker Value
Unknown

CVE-2017-18001

Disclosure Date: December 31, 2017 (last updated November 26, 2024)
Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys data, and consequently obtain remote root access, via the publicKey parameter to the /sendKey URI.
0
Attacker Value
Unknown

CVE-2017-8918

Disclosure Date: September 12, 2017 (last updated November 26, 2024)
XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows attackers to remotely view local files via a crafted template.xml file.
0
Attacker Value
Unknown

CVE-2017-6005

Disclosure Date: July 26, 2017 (last updated November 26, 2024)
Waves MaxxAudio, as installed on Dell laptops, adds a "WavesSysSvc" Windows service with File Version 1.1.6.0. This service has a vulnerability known as Unquoted Service Path. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system.
0
Attacker Value
Unknown

CVE-2017-7576

Disclosure Date: April 06, 2017 (last updated November 26, 2024)
DragonWave Horizon 1.01.03 wireless radios have hardcoded login credentials (such as the username of energetic and password of wireless) meant to allow the vendor to access the devices. These credentials can be used in the web interface or by connecting to the device via TELNET. This is fixed in recent versions including 1.4.8.
Attacker Value
Unknown

CVE-2015-4060

Disclosure Date: May 29, 2015 (last updated October 05, 2023)
Heap-based buffer overflow in the TermProxy (WLTermProxyService.exe) service in Wavelink ConnectPro allows remote attackers to execute arbitrary code via a large HTTP header.
0
Attacker Value
Unknown

CVE-2015-4059

Disclosure Date: May 29, 2015 (last updated October 05, 2023)
Heap-based buffer overflow in the License Server (LicenseServer.exe) in Wavelink Terminal Emulation (TE) allows remote attackers to execute arbitrary code via a large HTTP header.
0
Attacker Value
Unknown

CVE-2014-7039

Disclosure Date: October 16, 2014 (last updated October 05, 2023)
The Wild Women United (aka com.wildwomenunited) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-6933

Disclosure Date: October 04, 2014 (last updated October 05, 2023)
The Toraware Takojyou (aka ltd.pte.wavea.torawaretakojyou) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2013-5705

Disclosure Date: April 15, 2014 (last updated October 05, 2023)
apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header.
0
Attacker Value
Unknown

CVE-2013-3577

Disclosure Date: July 15, 2013 (last updated October 05, 2023)
SQL injection vulnerability in the Help Desk application in Wave EMBASSY Remote Administration Server (ERAS) allows remote attackers to execute arbitrary SQL commands via the ct100$4MainController$TextBoxSearchValue parameter (aka the search field).
0