Show filters
174 Total Results
Displaying 51-60 of 174
Sort by:
Attacker Value
Unknown
CVE-2019-9229
Disclosure Date: July 20, 2019 (last updated November 27, 2024)
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An internal interface exposed to the link-local address 169.254.254.253 allows attackers in the local network to access multiple quagga VTYs. Attackers can authenticate with the default 1234 password that cannot be changed, and can execute malicious and unauthorized actions.
0
Attacker Value
Unknown
CVE-2019-9228
Disclosure Date: July 19, 2019 (last updated November 08, 2023)
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A at least to 7.20A.252.062. The (1) management SSH and (2) management TELNET features allow remote attackers to cause a denial of service (connection slot exhaustion) via 5 unauthenticated connection attempts, because the maximum number of unauthenticated clients that can be configured is 5. NOTE: the vendor's position is that this is a "design choice.
0
Attacker Value
Unknown
CVE-2019-9231
Disclosure Date: July 18, 2019 (last updated November 27, 2024)
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions before 7.20A.202.307. A Cross-Site Request Forgery (CSRF) vulnerability in the management web interface allows remote attackers to execute malicious and unauthorized actions, because CSRFProtection=1 is not a default and is not documented.
0
Attacker Value
Unknown
CVE-2019-9230
Disclosure Date: July 18, 2019 (last updated November 27, 2024)
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.253. A cross-site scripting (XSS) vulnerability in the search function of the management web interface allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.
0
Attacker Value
Unknown
CVE-2019-13351
Disclosure Date: July 05, 2019 (last updated November 27, 2024)
posix/JackSocket.cpp in libjack in JACK2 1.9.1 through 1.9.12 (as distributed with alsa-plugins 1.1.7 and later) has a "double file descriptor close" issue during a failed connection attempt when jackd2 is not running. Exploitation success depends on multithreaded timing of that double close, which can result in unintended information disclosure, crashes, or file corruption due to having the wrong file associated with the file descriptor.
0
Attacker Value
Unknown
CVE-2019-13147
Disclosure Date: July 02, 2019 (last updated December 29, 2023)
In Audio File Library (aka audiofile) 0.3.6, there exists one NULL pointer dereference bug in ulaw2linear_buf in G711.cpp in libmodules.a that allows an attacker to cause a denial of service via a crafted file.
0
Attacker Value
Unknown
CVE-2019-7553
Disclosure Date: June 06, 2019 (last updated November 27, 2024)
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has Stored XSS in the Profile Update page via the My Name field.
0
Attacker Value
Unknown
CVE-2018-16216
Disclosure Date: April 25, 2019 (last updated November 27, 2024)
A command injection (missing input validation, escaping) in the monitoring or memory status web interface in AudioCodes 405HD (firmware 2.2.12) VoIP phone allows an authenticated remote attacker in the same network as the device to trigger OS commands (like starting telnetd or opening a reverse shell) via a POST request to the web server. In combination with another attack (unauthenticated password change), the attacker can circumvent the authentication requirement.
0
Attacker Value
Unknown
CVE-2018-16220
Disclosure Date: April 25, 2019 (last updated November 27, 2024)
Cross Site Scripting in different input fields (domain field and personal settings) in AudioCodes 405HD VoIP phone with firmware 2.2.12 allows an attacker (local or remote) to inject JavaScript into the web interface of the device by manipulating the phone book entries or manipulating the domain name sent to the device from the domain controller.
0
Attacker Value
Unknown
CVE-2018-16219
Disclosure Date: April 25, 2019 (last updated November 27, 2024)
A missing password verification in the web interface in AudioCodes 405HD VoIP phone with firmware 2.2.12 allows an remote attacker (in the same network as the device) to change the admin password without authentication via a POST request.
0