Show filters
70 Total Results
Displaying 51-60 of 70
Sort by:
Attacker Value
Unknown
CVE-2016-5805
Disclosure Date: February 13, 2017 (last updated November 26, 2024)
An issue was discovered in Delta Electronics WPLSoft, Versions prior to V2.42.11, ISPSoft, Versions prior to 3.02.11, and PMSoft, Versions prior to2.10.10. There are multiple instances of heap-based buffer overflows that may allow malicious files to cause the execution of arbitrary code or a denial of service.
0
Attacker Value
Unknown
CVE-2016-5802
Disclosure Date: February 13, 2017 (last updated November 26, 2024)
An issue was discovered in Delta Electronics WPLSoft, Versions prior to V2.42.11, ISPSoft, Versions prior to 3.02.11, and PMSoft, Versions prior to 2.10.10. Multiple instances of out-of-bounds write conditions may allow malicious files to be read and executed by the affected software.
0
Attacker Value
Unknown
CVE-2013-4732
Disclosure Date: June 30, 2013 (last updated November 08, 2023)
The administrative web server on the Digital Alert Systems DASDEC EAS device through 2.0-2 and the Monroe Electronics R189 One-Net EAS device through 2.0-2 uses predictable session ID values, which makes it easier for remote attackers to hijack sessions by sniffing the network. NOTE: VU#662676 states "Monroe Electronics could not reproduce this finding.
0
Attacker Value
Unknown
CVE-2013-4734
Disclosure Date: June 30, 2013 (last updated October 05, 2023)
dasdec_mkuser on the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 generates predictable passwords, which might make it easier for attackers to obtain non-administrative access via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-4733
Disclosure Date: June 30, 2013 (last updated October 05, 2023)
The web server on the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 allows remote attackers to obtain sensitive configuration and status information by reading log files.
0
Attacker Value
Unknown
CVE-2013-4735
Disclosure Date: June 30, 2013 (last updated October 05, 2023)
The Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 have a default password for an administrative account, which makes it easier for remote attackers to obtain access via an IP network.
0
Attacker Value
Unknown
CVE-2013-0137
Disclosure Date: June 30, 2013 (last updated October 05, 2023)
The default configuration of the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 contains a known SSH private key, which makes it easier for remote attackers to obtain root access, and spoof alerts, via an SSH session.
0
Attacker Value
Unknown
CVE-2012-4696
Disclosure Date: January 28, 2013 (last updated October 05, 2023)
Buffer overflow in Beijer ADP 6.5.0-180_R1967 and 6.5.1-186_R2942, and H-Designer 6.5.0 B180_R1967, allows local users to gain privileges by inserting a long string into a DLL file.
0
Attacker Value
Unknown
CVE-2008-7084
Disclosure Date: August 26, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in the web server 1.0 in Velocity Security Management System allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
0
Attacker Value
Unknown
CVE-2008-4874
Disclosure Date: November 01, 2008 (last updated October 04, 2023)
The web component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 has a back door "service" account with "service" as its password, which makes it easier for remote attackers to obtain access.
0