Show filters
887 Total Results
Displaying 41-50 of 887
Sort by:
Attacker Value
Unknown
CVE-2024-5632
Disclosure Date: July 09, 2024 (last updated July 09, 2024)
Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, create a WiFi network with a default password.
A user is neither advised to change it during the installation process, nor such a need is described in the manual. As the cameras from the same kit connect automatically, it is very probable for the default password to be left unchanged.
0
Attacker Value
Unknown
CVE-2024-5631
Disclosure Date: July 09, 2024 (last updated July 09, 2024)
Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, are transmitting user's login and password to a remote control service without using any encryption. This enables an on-path attacker to eavesdrop the credentials and subsequently obtain access to the video stream.
The credentials are being sent when a user decides to change his password in router's portal.
0
Attacker Value
Unknown
CVE-2024-36454
Disclosure Date: June 12, 2024 (last updated June 12, 2024)
Use of uninitialized resource issue exists in IPCOM EX2 Series (V01L0x Series) V01L07NF0201 and earlier, and IPCOM VE2 Series V01L07NF0201 and earlier. If this vulnerability is exploited, the system may be rebooted or suspended by receiving a specially crafted packet.
0
Attacker Value
Unknown
CVE-2024-31413
Disclosure Date: May 01, 2024 (last updated May 02, 2024)
Free of pointer not at start of buffer vulnerability exists in CX-One CX-One CXONE-AL[][]D-V4 (The version which was installed with a DVD ver. 4.61.1 or lower, and was updated through CX-One V4 auto update in January 2024 or prior) and Sysmac Studio SYSMAC-SE2[][][] (The version which was installed with a DVD ver. 1.56 or lower, and was updated through Sysmac Studio V1 auto update in January 2024 or prior). Opening a specially crafted project file may lead to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2024-3871
Disclosure Date: April 16, 2024 (last updated April 17, 2024)
The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements multiple features that are affected by command injections and stack overflows vulnerabilities.
Successful exploitation of these flaws would allow remote unauthenticated attackers to gain remote code execution with elevated privileges on the affected devices.
This issue affects DVW-W02W2-E2 through version 2.5.2.
0
Attacker Value
Unknown
CVE-2024-31373
Disclosure Date: April 15, 2024 (last updated April 15, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in E2Pdf.This issue affects e2pdf: from n/a through 1.20.27.
0
Attacker Value
Unknown
CVE-2024-0172
Disclosure Date: April 03, 2024 (last updated February 05, 2025)
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation.
0
Attacker Value
Unknown
CVE-2024-26475
Disclosure Date: March 14, 2024 (last updated January 24, 2025)
An issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allows a local attacker to cause a denial of service via the grub_sfs_read_extent function.
0
Attacker Value
Unknown
CVE-2024-0173
Disclosure Date: March 13, 2024 (last updated February 01, 2025)
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability to read the contents of non-SMM stack memory.
0
Attacker Value
Unknown
CVE-2024-0154
Disclosure Date: March 13, 2024 (last updated February 01, 2025)
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability to read the contents of non-SMM stack memory.
0