Show filters
545 Total Results
Displaying 421-430 of 545
Sort by:
Attacker Value
Unknown

CVE-2017-7305

Disclosure Date: April 04, 2017 (last updated November 08, 2023)
Riverbed RiOS through 9.6.0 does not require a bootloader password, which makes it easier for physically proximate attackers to defeat the secure-vault protection mechanism via a crafted boot. NOTE: the vendor believes that this does not meet the definition of a vulnerability. The product contains correct computational logic for a bootloader password; however, this password is optional to meet different customers' needs
0
Attacker Value
Unknown

CVE-2016-10305

Disclosure Date: March 30, 2017 (last updated November 26, 2024)
Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0, GigaPlus <= 3.2.3, GigaPro <= 1.4.1, StrataLink < 3.0, and StrataPro devices have a built-in, hidden root account, with a default password that was once stored in cleartext within a software update package on a Trango FTP server. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.
Attacker Value
Unknown

CVE-2016-10307

Disclosure Date: March 30, 2017 (last updated November 26, 2024)
Trango ApexLynx 2.0, ApexOrion 2.0, GigaLynx 2.0, GigaOrion 2.0, and StrataLink 3.0 devices have a built-in, hidden root account, with a default password for which the MD5 hash value is public (but the cleartext value is perhaps not yet public). This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.
Attacker Value
Unknown

CVE-2017-6068

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.
0
Attacker Value
Unknown

CVE-2017-6002

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body parameter.
0
Attacker Value
Unknown

CVE-2017-6013

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter.
0
Attacker Value
Unknown

CVE-2017-6066

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title parameter.
0
Attacker Value
Unknown

CVE-2017-6069

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.
0
Attacker Value
Unknown

CVE-2016-7145

Disclosure Date: March 07, 2017 (last updated November 26, 2024)
The m_authenticate function in ircd/m_authenticate.c in nefarious2 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.
0
Attacker Value
Unknown

CVE-2016-8344

Disclosure Date: February 13, 2017 (last updated November 26, 2024)
An issue was discovered in Honeywell Experion Process Knowledge System (PKS) platform: Experion PKS, Release 3xx and prior, Experion PKS, Release 400, Experion PKS, Release 410, Experion PKS, Release 430, and Experion PKS, Release 431. Experion PKS does not properly validate input. By sending a specially crafted packet, an attacker could cause the process to terminate. A successful exploit would prevent firmware uploads to the Series-C devices.
0