Show filters
1,310 Total Results
Displaying 491-500 of 1,310
Sort by:
Attacker Value
Unknown
CVE-2018-17591
Disclosure Date: October 02, 2018 (last updated November 27, 2024)
AirTies Air 5343v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
0
Attacker Value
Unknown
CVE-2018-17594
Disclosure Date: October 02, 2018 (last updated November 27, 2024)
AirTies Air 5443v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
0
Attacker Value
Unknown
CVE-2018-17589
Disclosure Date: October 02, 2018 (last updated November 27, 2024)
AirTies Air 5650 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
0
Attacker Value
Unknown
BIOS Write Protection Race Condition
Disclosure Date: October 02, 2018 (last updated November 27, 2024)
In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.
0
Attacker Value
Unknown
Ubiquiti airOS HTTP(S) unauthenticated arbitrary file upload
Disclosure Date: September 05, 2018 (last updated November 27, 2024)
The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in the following product versions (fixes released in July 2015, all prior versions are affected): airMAX AC 7.1.3; airMAX M (and airRouter) 5.6.2 XM/XW/TI, 5.5.11 XM/TI, and 5.5.10u2 XW; airGateway 1.1.5; airFiber AF24/AF24HD 2.2.1, AF5x 3.0.2.1, and AF5 2.2.1; airOS 4 XS2/XS5 4.0.4; and EdgeSwitch XP (formerly TOUGHSwitch) 1.3.2.
0
Attacker Value
Unknown
CVE-2018-15669
Disclosure Date: August 21, 2018 (last updated November 27, 2024)
An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. Its primary WebView instance implements "webView:decidePolicyForNavigationAction:request:frame:decisionListener:" such that requests from HTMLIFrameElements are blacklisted. However, other sub-classes of HTMLFrameOwnerElements are not forbidden by the policy. An attacker may abuse HTML plug-in elements within an email to trigger frame navigation requests that bypass this filter.
0
Attacker Value
Unknown
CVE-2018-15670
Disclosure Date: August 21, 2018 (last updated November 27, 2024)
An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. Its primary WebView instance implements "webView:decidePolicyForNavigationAction:request:frame:decisionListener:" such that OpenURL is the default URL handler. A navigation request is processed by the default URL handler only if the currentEvent is NX_LMOUSEUP or NX_OMOUSEUP. An attacker may abuse HTML elements with an EventHandler for a chance to validate navigation requests for URLs that are processed during the NX_LMOUSEUP event triggered by clicking an email.
0
Attacker Value
Unknown
CVE-2018-15667
Disclosure Date: August 21, 2018 (last updated November 27, 2024)
An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. It registers and uses the airmail:// URL scheme. The "send" command in the URL scheme allows an external application to send arbitrary emails from an active account without authentication. The handler has no restriction on who can use its functionality. The handler can be invoked using any method that invokes the URL handler such as a hyperlink in an email. The user is not prompted when the handler processes the "send" command, thus leading to automatic transmission of an attacker crafted email from the target account.
0
Attacker Value
Unknown
CVE-2018-15668
Disclosure Date: August 21, 2018 (last updated November 27, 2024)
An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. The "send" command in the airmail:// URL scheme allows an external application to send arbitrary emails from an active account. URL parameters for the "send" command with the "attachment_" prefix designate attachment parameters. If the value of an attachment parameter corresponds to an accessible file path, the file is attached to the outbound message. In addition, relative file paths are acceptable attachment parameter values. The handler can be invoked using any method that invokes the URL handler such as a hyperlink in an email. The user is not prompted when the handler processes the "send" command, thus leading to automatic transmission of an email with designated attachments from the target account to a target address.
0
Attacker Value
Unknown
CVE-2018-1000642
Disclosure Date: August 20, 2018 (last updated November 27, 2024)
FlightAirMap version <=v1.0-beta.21 contains a Cross Site Scripting (XSS) vulnerability in GET variable used within registration sub menu page that can result in unauthorised actions and access to data, stealing session information. This vulnerability appears to have been fixed in after commit 22b09a3.
0