Show filters
129 Total Results
Displaying 51-60 of 129
Sort by:
Attacker Value
Unknown

CVE-2020-7497

Disclosure Date: June 16, 2020 (last updated February 21, 2025)
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause arbitrary application execution when the computer starts.
Attacker Value
Unknown

CVE-2020-7493

Disclosure Date: June 16, 2020 (last updated February 21, 2025)
A CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause malicious code execution when opening the project file.
Attacker Value
Unknown

CVE-2020-7496

Disclosure Date: June 16, 2020 (last updated February 21, 2025)
A CWE-88: Argument Injection or Modification vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause unauthorized write access when opening the project file.
Attacker Value
Unknown

CVE-2020-7494

Disclosure Date: June 16, 2020 (last updated February 21, 2025)
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause malicious code execution when opening the project file.
Attacker Value
Unknown

CVE-2019-19148

Disclosure Date: March 20, 2020 (last updated February 21, 2025)
Tellabs Optical Line Terminal (OLT) 1150 devices allow Remote Command Execution via the -l option to TELNET or SSH. Tellabs has addressed this issue in the SR30.1 and SR31.1 release on February 18, 2020.
Attacker Value
Unknown

CVE-2017-17516

Disclosure Date: December 14, 2017 (last updated November 26, 2024)
scripts/inspect_webbrowser.py in Reddit Terminal Viewer (RTV) 1.19.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
0
Attacker Value
Unknown

CVE-2016-10369

Disclosure Date: May 08, 2017 (last updated November 08, 2023)
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).
0
Attacker Value
Unknown

CVE-2017-6356

Disclosure Date: March 20, 2017 (last updated November 26, 2024)
Palo Alto Networks Terminal Services (aka TS) Agent 6.0, 7.0, and 8.0 before 8.0.1 uses weak permissions for unspecified resources, which allows attackers to obtain sensitive session information via unknown vectors.
Attacker Value
Unknown

CVE-2017-5329

Disclosure Date: January 27, 2017 (last updated November 25, 2024)
Palo Alto Networks Terminal Services Agent before 7.0.7 allows local users to gain privileges via vectors that trigger an out-of-bounds write operation.
Attacker Value
Unknown

CVE-2017-5328

Disclosure Date: January 27, 2017 (last updated November 25, 2024)
Palo Alto Networks Terminal Services Agent before 7.0.7 allows attackers to spoof arbitrary users via unspecified vectors.