Show filters
1,310 Total Results
Displaying 401-410 of 1,310
Sort by:
Attacker Value
Unknown
CVE-2014-8322
Disclosure Date: January 31, 2020 (last updated February 21, 2025)
Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attackers to execute arbitrary code via a crafted length parameter value.
0
Attacker Value
Unknown
CVE-2016-2032
Disclosure Date: January 31, 2020 (last updated February 21, 2025)
A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called RabbitMQ, which could let a malicious user obtain sensitive information. This interface listens on TCP port 15672 and 55672
0
Attacker Value
Unknown
CVE-2019-13000
Disclosure Date: January 31, 2020 (last updated February 21, 2025)
Eclair through 0.3 allows attackers to trigger loss of funds because of Incorrect Access Control. NOTE: README.md states "it is beta-quality software and don't put too much money in it."
0
Attacker Value
Unknown
CVE-2016-2031
Disclosure Date: January 31, 2020 (last updated February 21, 2025)
Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient checking of parameters, which could allow a malicious user to bypass security restrictions, obtain sensitive information, perform unauthorized actions and execute arbitrary code.
0
Attacker Value
Unknown
CVE-2013-5637
Disclosure Date: January 07, 2020 (last updated February 21, 2025)
PQI AirCard has persistent XSS
0
Attacker Value
Unknown
CVE-2013-3691
Disclosure Date: December 11, 2019 (last updated November 27, 2024)
AirLive POE-2600HD allows remote attackers to cause a denial of service (device reset) via a long URL.
0
Attacker Value
Unknown
CVE-2019-19040
Disclosure Date: November 17, 2019 (last updated November 27, 2024)
KairosDB through 1.2.2 has XSS in view.html because of showErrorMessage in js/graph.js, as demonstrated by view.html?q= with a '"sampling":{"value":"<script>' substring.
0
Attacker Value
Unknown
CVE-2019-15356
Disclosure Date: November 14, 2019 (last updated November 27, 2024)
The Lava Flair Z1 Android device with a build fingerprint of LAVA/Z1/Z1:8.1.0/O11019/1536680131:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
0
Attacker Value
Unknown
CVE-2019-15341
Disclosure Date: November 14, 2019 (last updated November 27, 2024)
The Tecno Camon iAir 2 Plus Android device with a build fingerprint of TECNO/H622/TECNO-ID3k:8.1.0/O11019/E-180914V83:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.11). This app contains an exported service named com.lovelyfont.manager.service.FunctionService that allows any app co-located on the device to supply the file path to a Dalvik Executable (DEX) file which it will dynamically load within its own process and execute in with its own system privileges. This app cannot be disabled by the user and the attack can be performed by a zero-permission app. Executing commands as the system user can allow a third-party app to video record the user's screen, factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the Graphical User Interface (GUI), and obtains the user's text messages, and more. Executing code as the system user can allow a third-party app…
0
Attacker Value
Unknown
CVE-2019-15333
Disclosure Date: November 14, 2019 (last updated November 27, 2024)
The Lava Flair Z1 Android device with a build fingerprint of LAVA/Z1/Z1:8.1.0/O11019/1536680131:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.
0