Show filters
64 Total Results
Displaying 51-60 of 64
Sort by:
Attacker Value
Unknown
CVE-2019-15825
Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The wps-hide-login plugin before 1.5.3 for WordPress has an action=rp&key&login protection bypass.
0
Attacker Value
Unknown
CVE-2019-3929
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.
0
Attacker Value
Unknown
CVE-2019-3930
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to a stack buffer overflow in libAwgCgi.so's PARSERtoCHAR function. A remote, unauthenticated attacker can use this vulnerability to execute arbitrary code as root via a crafted request to the return.cgi endpoint.
0
Attacker Value
Unknown
CVE-2018-7546
Disclosure Date: July 18, 2018 (last updated November 27, 2024)
wpsmain.dll in Kingsoft WPS Office 2016 and Jinshan PDF 10.1.0.6621 allows remote attackers to cause a denial of service via a crafted pdf file.
0
Attacker Value
Unknown
CVE-2018-6400
Disclosure Date: March 12, 2018 (last updated November 26, 2024)
Kingsoft WPS Office Free 10.2.0.5978 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of \\.\pipe\WPSCloudSvr\WpsCloudSvr -- an "insecurely created named pipe." Ensures full access to Everyone users group.
0
Attacker Value
Unknown
CVE-2018-6390
Disclosure Date: January 29, 2018 (last updated November 26, 2024)
The WStr::assign function in kso.dll in Kingsoft WPS Office 10.1.0.7106 and 10.2.0.5978 does not validate the size of the source memory block before an _copy call, which allows remote attackers to cause a denial of service (access violation and application crash) via a crafted (a) web page, (b) office document, or (c) .rtf file.
0
Attacker Value
Unknown
CVE-2018-6217
Disclosure Date: January 25, 2018 (last updated November 26, 2024)
The WStr::_alloc_iostr_data() function in kso.dll in Kingsoft WPS Office 10.1.0.7106 and 10.2.0.5978 allows remote attackers to cause a denial of service (application crash) via a crafted (a) web page, (b) office document, or (c) .rtf file.
0
Attacker Value
Unknown
CVE-2017-17967
Disclosure Date: December 28, 2017 (last updated November 26, 2024)
pptreader.dll in Kingsoft WPS Office 10.1.0.6930 allows remote attackers to cause a denial of service via a crafted PPT file, aka CNVD-2017-35482.
0
Attacker Value
Unknown
CVE-2016-1000155
Disclosure Date: October 10, 2016 (last updated November 25, 2024)
Reflected XSS in wordpress plugin wpsolr-search-engine v7.6
0
Attacker Value
Unknown
CVE-2011-5237
Disclosure Date: November 06, 2012 (last updated October 05, 2023)
PayPal WPS ToolKit does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
0