Show filters
97 Total Results
Displaying 51-60 of 97
Sort by:
Attacker Value
Unknown

A broken access control vulnerability discovered in Smart Battery A4

Disclosure Date: September 25, 2019 (last updated November 08, 2023)
A broken access control vulnerability in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7.9 allows an attacker to get/reset administrator’s password without any authentication.
Attacker Value
Unknown

Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It …

Disclosure Date: June 03, 2019 (last updated November 27, 2024)
Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to add malicious email sources into whitelist via user/save_list.php?ACSION=&type=email&category=white&locate=big5&cmd=add&new=hacker@socialengineering.com&new_memo=&add=%E6%96%B0%E5%A2%9E without any authorizes.
0
Attacker Value
Unknown

Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It …

Disclosure Date: June 03, 2019 (last updated November 27, 2024)
Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to elevate privilege of specific account via useradmin/cf_new.cgi?chief=&wk_group=full&cf_name=test&cf_account=test&cf_email=&cf_acl=Management&apply_lang=&dn= without any authorizes.
0
Attacker Value
Unknown

SQL Injection exists in MailSherlock before 1.5.235 for OAKlouds

Disclosure Date: February 11, 2019 (last updated November 27, 2024)
SQL Injection exists in MailSherlock before 1.5.235 for OAKlouds allows an unauthenticated user to extract the subjects of the emails of other users within the enterprise via the select_mid parameter in an letgo.cgi request.
0
Attacker Value
Unknown

CVE-2018-19323

Disclosure Date: December 21, 2018 (last updated June 29, 2024)
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).
Attacker Value
Unknown

CVE-2018-19322

Disclosure Date: December 21, 2018 (last updated June 29, 2024)
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.
Attacker Value
Unknown

CVE-2018-19320

Disclosure Date: December 21, 2018 (last updated June 29, 2024)
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system.
Attacker Value
Unknown

CVE-2018-19321

Disclosure Date: December 21, 2018 (last updated June 29, 2024)
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.
Attacker Value
Unknown

CVE-2018-18871

Disclosure Date: December 20, 2018 (last updated November 27, 2024)
Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow a remote attacker (in the same network as the device) to change the admin password without authentication (and without knowing the original password).
0
Attacker Value
Unknown

CVE-2017-7908

Disclosure Date: October 02, 2018 (last updated November 27, 2024)
A heap-based buffer overflow exists in the third-party product Gigasoft, v5 and prior, included in GE Communicator 3.15 and prior. A malicious HTML file that loads the ActiveX controls can trigger the vulnerability via unchecked function calls.
0