Show filters
1,310 Total Results
Displaying 471-480 of 1,310
Sort by:
Attacker Value
Unknown
CVE-2019-1675
Disclosure Date: February 07, 2019 (last updated November 27, 2024)
A vulnerability in the default configuration of the Cisco Aironet Active Sensor could allow an unauthenticated, remote attacker to restart the sensor. The vulnerability is due to a default local account with a static password. The account has privileges only to reboot the device. An attacker could exploit this vulnerability by guessing the account name and password to access the CLI. A successful exploit could allow the attacker to reboot the device repeatedly, creating a denial of service (DoS) condition. It is not possible to change the configuration or view sensitive data with this account. Versions prior to DNAC1.2.8 are affected.
0
Attacker Value
Unknown
CVE-2017-17836
Disclosure Date: January 23, 2019 (last updated November 08, 2023)
In Apache Airflow 1.8.2 and earlier, an experimental Airflow feature displayed authenticated cookies, as well as passwords to databases used by Airflow. An attacker who has limited access to airflow, whether it be via XSS or by leaving a machine unlocked can exfiltrate all credentials from the system.
0
Attacker Value
Unknown
CVE-2018-20245
Disclosure Date: January 23, 2019 (last updated November 08, 2023)
The LDAP auth backend (airflow.contrib.auth.backends.ldap_auth) prior to Apache Airflow 1.10.1 was misconfigured and contained improper checking of exceptions which disabled server certificate checking.
0
Attacker Value
Unknown
CVE-2017-17835
Disclosure Date: January 23, 2019 (last updated November 08, 2023)
In Apache Airflow 1.8.2 and earlier, a CSRF vulnerability allowed for a remote command injection on a default install of Airflow.
0
Attacker Value
Unknown
CVE-2017-15720
Disclosure Date: January 23, 2019 (last updated November 08, 2023)
In Apache Airflow 1.8.2 and earlier, an authenticated user can execute code remotely on the Airflow webserver by creating a special object.
0
Attacker Value
Unknown
CVE-2019-3910
Disclosure Date: January 18, 2019 (last updated November 27, 2024)
Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script. Unauthenticated remote users can use the bypass to access some administrator functionality such as configuring update sources and rebooting the device.
0
Attacker Value
Unknown
CVE-2019-6462
Disclosure Date: January 16, 2019 (last updated November 08, 2023)
An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized.
0
Attacker Value
Unknown
CVE-2019-6461
Disclosure Date: January 16, 2019 (last updated November 08, 2023)
An issue was discovered in cairo 1.16.0. There is an assertion problem in the function _cairo_arc_in_direction in the file cairo-arc.c.
0
Attacker Value
Unknown
CVE-2018-19876
Disclosure Date: December 05, 2018 (last updated November 27, 2024)
cairo 1.16.0, in cairo_ft_apply_variations() in cairo-ft-font.c, would free memory using a free function incompatible with WebKit's fastMalloc, leading to an application crash with a "free(): invalid pointer" error.
0
Attacker Value
Unknown
CVE-2018-0381
Disclosure Date: October 17, 2018 (last updated November 27, 2024)
A vulnerability in the Cisco Aironet Series Access Points (APs) software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to a deadlock condition that may occur when an affected AP attempts to dequeue aggregated traffic that is destined to an attacker-controlled wireless client. An attacker who can successfully transition between multiple Service Set Identifiers (SSIDs) hosted on the same AP while replicating the required traffic patterns could trigger the deadlock condition. A watchdog timer that detects the condition will trigger a reload of the device, resulting in a DoS condition while the device restarts.
0