Show filters
813 Total Results
Displaying 371-380 of 813
Sort by:
Attacker Value
Unknown

CVE-2020-28402

Disclosure Date: January 29, 2021 (last updated November 28, 2024)
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access Launcher Configuration Panel.
Attacker Value
Unknown

CVE-2020-28403

Disclosure Date: January 29, 2021 (last updated February 22, 2025)
A Cross-Site Request Forgery (CSRF) vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an attacker to change the privileges of any user of the application. This can be used to grant himself administrative role or remove the administrative account of the application.
Attacker Value
Unknown

CVE-2020-28401

Disclosure Date: January 29, 2021 (last updated November 28, 2024)
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access WIP details about jobs he should not have access to.
Attacker Value
Unknown

CVE-2020-28406

Disclosure Date: January 29, 2021 (last updated November 28, 2024)
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access details about jobs he should not have access to via the Audit Trail Feature.
Attacker Value
Unknown

CVE-2020-28404

Disclosure Date: January 29, 2021 (last updated November 28, 2024)
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access the Billing page without the appropriate privileges.
Attacker Value
Unknown

CVE-2021-1353

Disclosure Date: January 20, 2021 (last updated February 22, 2025)
A vulnerability in the IPv4 protocol handling of Cisco StarOS could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory leak that occurs during packet processing. An attacker could exploit this vulnerability by sending a series of crafted IPv4 packets through an affected device. A successful exploit could allow the attacker to exhaust the available memory and cause an unexpected restart of the npusim process, leading to a DoS condition on the affected device.
Attacker Value
Unknown

CVE-2020-14409

Disclosure Date: January 19, 2021 (last updated February 22, 2025)
SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file.
Attacker Value
Unknown

CVE-2020-36193

Disclosure Date: January 18, 2021 (last updated February 22, 2025)
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.
Attacker Value
Unknown

CVE-2021-1145

Disclosure Date: January 13, 2021 (last updated February 22, 2025)
A vulnerability in the Secure FTP (SFTP) of Cisco StarOS for Cisco ASR 5000 Series Routers could allow an authenticated, remote attacker to read arbitrary files on an affected device. To exploit this vulnerability, the attacker would need to have valid credentials on the affected device. The vulnerability is due to insecure handling of symbolic links. An attacker could exploit this vulnerability by sending a crafted SFTP command to an affected device. A successful exploit could allow the attacker to read arbitrary files on the affected device.
Attacker Value
Unknown

CVE-2020-36161

Disclosure Date: January 06, 2021 (last updated November 28, 2024)
An issue was discovered in Veritas APTARE 10.4 before 10.4P9 and 10.5 before 10.5P3. By default, on Windows systems, users can create directories under C:\. A low privileged user can create a directory at the configuration file locations. When the Windows system restarts, a malicious OpenSSL engine could exploit arbitrary code execution as SYSTEM. This gives the attacker administrator access on the system, allowing the attacker (by default) to access all data, access all installed applications, etc.