Show filters
50 Total Results
Displaying 41-50 of 50
Sort by:
Attacker Value
Unknown

CVE-2020-21525

Disclosure Date: September 30, 2020 (last updated February 22, 2025)
Halo V1.1.3 is affected by: Arbitrary File reading. In an interface that reads files in halo v1.1.3, a directory traversal check is performed on the input path parameter, but the startsWith function can be used to bypass it.
Attacker Value
Unknown

CVE-2020-19007

Disclosure Date: August 26, 2020 (last updated February 22, 2025)
Halo blog 1.2.0 allows users to submit comments on blog posts via /api/content/posts/comments. The javascript code supplied by the attacker will then execute in the victim user's browser.
Attacker Value
Unknown

CVE-2019-19999

Disclosure Date: December 26, 2019 (last updated November 27, 2024)
Halo before 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFER_RESOLVER is not used in the FreeMarker configuration.
Attacker Value
Unknown

CVE-2019-16890

Disclosure Date: September 25, 2019 (last updated November 27, 2024)
Halo 1.1.0 has XSS via a crafted authorUrl in JSON data to api/content/posts/comments.
Attacker Value
Unknown

Eaton Halo Home Android App Insecure Storage

Disclosure Date: May 22, 2019 (last updated November 27, 2024)
The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear text file. This file persists until the user logs out of the application and reboots the device. This vulnerability can allow an attacker to impersonate the legitimate user by reusing the stored OAuth token, thus allowing them to view and change the user's personal information stored in the backend cloud service. The attacker would first need to gain physical control of the Android device or compromise it with a malicious app.
Attacker Value
Unknown

CVE-2018-11011

Disclosure Date: May 12, 2018 (last updated November 26, 2024)
ruibaby Halo 0.0.2 has stored XSS via the commentAuthor field to FrontCommentController.java.
0
Attacker Value
Unknown

CVE-2018-11012

Disclosure Date: May 12, 2018 (last updated November 26, 2024)
ruibaby Halo 0.0.2 has stored XSS via the loginName and loginPwd parameters in a failed login attempt to AdminController.java.
0
Attacker Value
Unknown

CVE-2005-1741

Disclosure Date: May 24, 2005 (last updated February 22, 2025)
Gearbox Software Halo: Combat Evolved 1.6 allows remote attackers to cause a denial of service (infinite loop) via malformed data.
0
Attacker Value
Unknown

CVE-2004-1539

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Halo: Combat Evolved 1.05 and earlier allows remote game servers to cause a denial of service (client crash) via a long value in a game server reply, which triggers a NULL dereference.
0
Attacker Value
Unknown

CVE-2004-1667

Disclosure Date: September 09, 2004 (last updated February 22, 2025)
Off-by-one error in Halo Combat Evolved 1.04 and earlier allows remote attackers to cause a denial of service (server crash) via a long client response.
0