Show filters
97 Total Results
Displaying 61-70 of 97
Sort by:
Attacker Value
Unknown
CVE-2018-1000666
Disclosure Date: September 06, 2018 (last updated November 08, 2023)
GIG Technology NV JumpScale Portal 7 version before commit 15443122ed2b1cbfd7bdefc048bf106f075becdb contains a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in method: notifySpaceModification; that can result in Improper validation of parameters results in command execution. This attack appear to be exploitable via Network connectivity, required minimal auth privileges (everyone can register an account). This vulnerability appears to have been fixed in After commit 15443122ed2b1cbfd7bdefc048bf106f075becdb.
0
Attacker Value
Unknown
GIGABYTE BRIX UEFI firmware is not cryptographically signed
Disclosure Date: July 09, 2018 (last updated November 27, 2024)
GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the system firmware. Additionally, the firmware updates are served over HTTP. An attacker can make arbitrary modifications to firmware images without being detected.
0
Attacker Value
Unknown
GIGABYTE BRIX UEFI firmware fails to securely implement BIOS write protection
Disclosure Date: July 09, 2018 (last updated November 27, 2024)
GIGABYTE BRIX UEFI firmware for the GB-BSi7H-6500 (version F6) and GB-BXi7-5775 (version F2) platforms does not securely implement BIOSWE, BLE, SMM_BWP, and PRx features. As a result, the BIOS is not protected from arbitrary write access and may permit modifications to the SPI flash.
0
Attacker Value
Unknown
CVE-2017-17576
Disclosure Date: December 13, 2017 (last updated November 26, 2024)
FS Gigs Script 1.0 has SQL Injection via the browse-category.php cat parameter, browse-scategory.php sc parameter, or service-provider.php ser parameter.
0
Attacker Value
Unknown
CVE-2017-12953
Disclosure Date: August 28, 2017 (last updated November 26, 2024)
The gig::Instrument::UpdateRegionKeyTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (invalid memory write and application crash) via a crafted gig file.
0
Attacker Value
Unknown
CVE-2017-12951
Disclosure Date: August 28, 2017 (last updated November 26, 2024)
The gig::DimensionRegion::CreateVelocityTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted gig file.
0
Attacker Value
Unknown
CVE-2017-12954
Disclosure Date: August 28, 2017 (last updated November 26, 2024)
The gig::Region::GetSampleFromWavePool function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted gig file.
0
Attacker Value
Unknown
CVE-2017-12952
Disclosure Date: August 28, 2017 (last updated November 26, 2024)
The LoadString function in helper.h in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted gig file.
0
Attacker Value
Unknown
CVE-2016-7844
Disclosure Date: August 02, 2017 (last updated November 08, 2023)
GigaCC OFFICE ver.2.3 and earlier allows remote attackers to execute arbitrary OS commands via specially crafted mail template.
0
Attacker Value
Unknown
CVE-2016-7845
Disclosure Date: August 02, 2017 (last updated November 08, 2023)
GigaCC OFFICE ver.2.3 and earlier allows remote attackers to upload arbitrary files as a user profile image, which may be exploited for unauthorized file sharing.
0