Show filters
287 Total Results
Displaying 41-50 of 287
Sort by:
Attacker Value
Unknown
Ubiquiti airOS HTTP(S) unauthenticated arbitrary file upload
Disclosure Date: September 05, 2018 (last updated November 27, 2024)
The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in the following product versions (fixes released in July 2015, all prior versions are affected): airMAX AC 7.1.3; airMAX M (and airRouter) 5.6.2 XM/XW/TI, 5.5.11 XM/TI, and 5.5.10u2 XW; airGateway 1.1.5; airFiber AF24/AF24HD 2.2.1, AF5x 3.0.2.1, and AF5 2.2.1; airOS 4 XS2/XS5 4.0.4; and EdgeSwitch XP (formerly TOUGHSwitch) 1.3.2.
0
Attacker Value
Unknown
CVE-2018-6643
Disclosure Date: August 28, 2018 (last updated November 27, 2024)
Infoblox NetMRI 7.1.1 has Reflected Cross-Site Scripting via the /api/docs/index.php query parameter.
0
Attacker Value
Unknown
CVE-2018-8032
Disclosure Date: August 02, 2018 (last updated November 08, 2023)
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
0
Attacker Value
Unknown
CVE-2018-1000613
Disclosure Date: July 09, 2018 (last updated November 08, 2023)
Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result in the execution of unexpected code. This attack appear to be exploitable via A handcrafted private key can include references to unexpected classes which will be picked up from the class path for the executing application. This vulnerability appears to have been fixed in 1.60 and later.
0
Attacker Value
Unknown
CVE-2013-3017
Disclosure Date: July 09, 2018 (last updated November 27, 2024)
IBM Tivoli Application Dependency Discovery Manager (TADDM) before 7.2.1.5 and 7.2.x before 7.2.2 make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging support for weak SSL ciphers. IBM X-Force ID: 84353.
0
Attacker Value
Unknown
CVE-2018-10658
Disclosure Date: June 26, 2018 (last updated November 26, 2024)
There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which causes a denial of service (crash). The crash arises from code inside libdbus-send.so shared object or similar.
0
Attacker Value
Unknown
CVE-2018-10659
Disclosure Date: June 26, 2018 (last updated November 26, 2024)
There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which allows remote attackers to cause a denial of service (crash) by sending a crafted command which will result in a code path that calls the UND undefined ARM instruction.
0
Attacker Value
Unknown
CVE-2018-10660
Disclosure Date: June 26, 2018 (last updated November 26, 2024)
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
0
Attacker Value
Unknown
CVE-2018-10661
Disclosure Date: June 26, 2018 (last updated November 26, 2024)
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
0
Attacker Value
Unknown
CVE-2018-10663
Disclosure Date: June 26, 2018 (last updated November 26, 2024)
An issue was discovered in multiple models of Axis IP Cameras. There is an Incorrect Size Calculation.
0