Show filters
664 Total Results
Displaying 411-420 of 664
Sort by:
Attacker Value
Unknown

CVE-2019-14984

Disclosure Date: August 13, 2019 (last updated November 27, 2024)
eQ-3 Homematic CCU2 and CCU3 with the XML-API through 1.2.0 AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface, because the undocumented addons/xmlapi/exec.cgi script uses CMD_EXEC to execute TCL code from a POST request.
0
Attacker Value
Unknown

CVE-2019-13097

Disclosure Date: July 22, 2019 (last updated November 27, 2024)
The application API of Cat Runner Decorate Home version 2.8.0 for Android does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable. Attackers can manipulate users' score parameters exchanged between client and server.
0
Attacker Value
Unknown

CVE-2019-6160

Disclosure Date: July 16, 2019 (last updated November 27, 2024)
A vulnerability in various versions of Iomega and LenovoEMC NAS products could allow an unauthenticated user to access files on NAS shares via the API.
0
Attacker Value
Unknown

CVE-2019-12280

Disclosure Date: June 25, 2019 (last updated November 27, 2024)
PC-Doctor Toolbox before 7.3 has an Uncontrolled Search Path Element.
0
Attacker Value
Unknown

CVE-2019-3735

Disclosure Date: June 20, 2019 (last updated November 27, 2024)
Dell SupportAssist for Business PCs version 2.0 and Dell SupportAssist for Home PCs version 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, and 3.2.1 contain an Improper Privilege Management Vulnerability. A malicious local user can exploit this vulnerability by inheriting a system thread using a leaked thread handle to gain system privileges on the affected machine.
Attacker Value
Unknown

Incorrect pviilege assignment in the 3rd party pairing mechanism of the Bosch S…

Disclosure Date: May 29, 2019 (last updated November 27, 2024)
A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.907 that may result in a restricted app obtaining default app permissions. In order to exploit the vulnerability, the adversary needs to have successfully paired an app, which requires user interaction.
Attacker Value
Unknown

Improper access control in the backup mechanism of the Bosch Smart Home Control…

Disclosure Date: May 29, 2019 (last updated November 27, 2024)
A potential improper access control vulnerability exists in the backup mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in unauthorized download of a backup. In order to exploit the vulnerability, the adversary needs to download the backup directly after a backup triggered by a legitimate user has been completed.
Attacker Value
Unknown

Improper access control in the JSON-RPC interface of the Bosch Smart Home Contr…

Disclosure Date: May 29, 2019 (last updated November 27, 2024)
A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in a successful denial of service of the SHC and connected sensors and actuators. In order to exploit the vulnerability, the adversary needs to have successfully paired an app or service, which requires user interaction.
Attacker Value
Unknown

Improper access control in the JSON-RPC interface of the Bosch Smart Home Contr…

Disclosure Date: May 29, 2019 (last updated November 27, 2024)
A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in reading or modification of the SHC's configuration or triggering and restoring backups. In order to exploit the vulnerability, the adversary needs to have successfully paired an app or service, which requires user interaction.
Attacker Value
Unknown

Incorrect privilege assignment in the app pairing mechanism of the Bosch Smart …

Disclosure Date: May 29, 2019 (last updated November 27, 2024)
A potential incorrect privilege assignment vulnerability exists in the app pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in elevated privileges of the adversary's choosing. In order to exploit the vulnerability, the adversary needs physical access to the SHC during the attack.