Show filters
97 Total Results
Displaying 61-70 of 97
Sort by:
Attacker Value
Unknown

CVE-2018-1000666

Disclosure Date: September 06, 2018 (last updated November 08, 2023)
GIG Technology NV JumpScale Portal 7 version before commit 15443122ed2b1cbfd7bdefc048bf106f075becdb contains a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in method: notifySpaceModification; that can result in Improper validation of parameters results in command execution. This attack appear to be exploitable via Network connectivity, required minimal auth privileges (everyone can register an account). This vulnerability appears to have been fixed in After commit 15443122ed2b1cbfd7bdefc048bf106f075becdb.
0
Attacker Value
Unknown

GIGABYTE BRIX UEFI firmware is not cryptographically signed

Disclosure Date: July 09, 2018 (last updated November 27, 2024)
GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the system firmware. Additionally, the firmware updates are served over HTTP. An attacker can make arbitrary modifications to firmware images without being detected.
0
Attacker Value
Unknown

GIGABYTE BRIX UEFI firmware fails to securely implement BIOS write protection

Disclosure Date: July 09, 2018 (last updated November 27, 2024)
GIGABYTE BRIX UEFI firmware for the GB-BSi7H-6500 (version F6) and GB-BXi7-5775 (version F2) platforms does not securely implement BIOSWE, BLE, SMM_BWP, and PRx features. As a result, the BIOS is not protected from arbitrary write access and may permit modifications to the SPI flash.
0
Attacker Value
Unknown

CVE-2017-17576

Disclosure Date: December 13, 2017 (last updated November 26, 2024)
FS Gigs Script 1.0 has SQL Injection via the browse-category.php cat parameter, browse-scategory.php sc parameter, or service-provider.php ser parameter.
Attacker Value
Unknown

CVE-2017-12953

Disclosure Date: August 28, 2017 (last updated November 26, 2024)
The gig::Instrument::UpdateRegionKeyTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (invalid memory write and application crash) via a crafted gig file.
0
Attacker Value
Unknown

CVE-2017-12951

Disclosure Date: August 28, 2017 (last updated November 26, 2024)
The gig::DimensionRegion::CreateVelocityTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted gig file.
0
Attacker Value
Unknown

CVE-2017-12954

Disclosure Date: August 28, 2017 (last updated November 26, 2024)
The gig::Region::GetSampleFromWavePool function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted gig file.
0
Attacker Value
Unknown

CVE-2017-12952

Disclosure Date: August 28, 2017 (last updated November 26, 2024)
The LoadString function in helper.h in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted gig file.
0
Attacker Value
Unknown

CVE-2016-7844

Disclosure Date: August 02, 2017 (last updated November 08, 2023)
GigaCC OFFICE ver.2.3 and earlier allows remote attackers to execute arbitrary OS commands via specially crafted mail template.
0
Attacker Value
Unknown

CVE-2016-7845

Disclosure Date: August 02, 2017 (last updated November 08, 2023)
GigaCC OFFICE ver.2.3 and earlier allows remote attackers to upload arbitrary files as a user profile image, which may be exploited for unauthorized file sharing.
0