Show filters
53 Total Results
Displaying 41-50 of 53
Sort by:
Attacker Value
Unknown
CVE-2019-17218
Disclosure Date: October 06, 2019 (last updated November 27, 2024)
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the communication to the web service is unencrypted via http. An attacker is able to intercept and sniff communication to the web service.
0
Attacker Value
Unknown
CVE-2019-17219
Disclosure Date: October 06, 2019 (last updated November 27, 2024)
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the device does not enforce any authentication. An adjacent attacker is able to use the network interface without proper access control.
0
Attacker Value
Unknown
CVE-2019-17215
Disclosure Date: October 06, 2019 (last updated November 27, 2024)
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no bruteforce protection (e.g., lockout) established. An attacker might be able to bruteforce the password to authenticate on the device.
0
Attacker Value
Unknown
CVE-2019-17217
Disclosure Date: October 06, 2019 (last updated November 27, 2024)
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no CSRF protection established on the web service.
0
Attacker Value
Unknown
CVE-2018-13674
Disclosure Date: July 09, 2018 (last updated November 27, 2024)
The mintToken function of a smart contract implementation for ComBillAdvancedToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
0
Attacker Value
Unknown
CVE-2017-6019
Disclosure Date: April 07, 2017 (last updated November 26, 2024)
An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions prior to V3.03 BN 830. A series of rapid requests to the device may cause it to reboot.
0
Attacker Value
Unknown
CVE-2011-4788
Disclosure Date: January 13, 2012 (last updated October 04, 2023)
Absolute path traversal vulnerability in the web interface on HP StorageWorks P2000 G3 MSA array systems allows remote attackers to read arbitrary files via a pathname in the URI.
0
Attacker Value
Unknown
CVE-2007-2848
Disclosure Date: May 24, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in the SetPath function in the shComboBox ActiveX control (shcmb80.ocx) in Sky Software Shell MegaPack ActiveX 8.0 allows remote attackers to execute arbitrary code via a long argument. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2005-4419
Disclosure Date: December 20, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in CategoryResults.cfm in Honeycomb Archive and Honeycomb Archive Enterprise 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) series, (2) cat_parent, (3) cat, and (4) div parameters.
0
Attacker Value
Unknown
CVE-2005-4420
Disclosure Date: December 20, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Honeycomb Archive Enterprise 3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the keyword parameter in search.cfm.
0