Show filters
144 Total Results
Displaying 61-70 of 144
Sort by:
Attacker Value
Unknown
CVE-2018-16618
Disclosure Date: June 19, 2019 (last updated November 27, 2024)
VTech Storio Max before 56.D3JM6 allows remote command execution via shell metacharacters in an Android activity name. It exposes the storeintenttranslate.x service on port 1668 listening for requests on localhost. Requests submitted to this service are checked for a string of random characters followed by the name of an Android activity to start. Activities are started by inserting their name into a string that is executed in a shell command. By inserting metacharacters this can be exploited to run arbitrary commands as root. The requests also match those of the HTTP protocol and can be triggered on any web page rendered on the device by requesting resources stored at an http://127.0.0.1:1668/ URI, as demonstrated by the http://127.0.0.1:1668/dacdb70556479813fab2d92896596eef?';{ping,example.org}' URL.
0
Attacker Value
Unknown
CVE-2018-8047
Disclosure Date: June 06, 2019 (last updated November 27, 2024)
vtiger CRM 7.0.1 is affected by one reflected Cross-Site Scripting (XSS) vulnerability affecting version 7.0.1 and probably prior versions. This vulnerability could allow remote unauthenticated attackers to inject arbitrary web script or HTML via index.php?module=Contacts&view=List (app parameter).
0
Attacker Value
Unknown
CVE-2016-10754
Disclosure Date: May 24, 2019 (last updated November 27, 2024)
modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.
0
Attacker Value
Unknown
CVE-2019-11057
Disclosure Date: May 17, 2019 (last updated November 08, 2023)
SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL commands.
0
Attacker Value
Unknown
CVE-2019-5009
Disclosure Date: January 04, 2019 (last updated November 27, 2024)
Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG format and has a size of 150x40. One can put PHP code into the image; PHP code can be executed using "<? ?>" tags, as demonstrated by a CompanyDetailsSave action. This bypasses the bad-file-extensions protection mechanism. It is related to actions/CompanyDetailsSave.php, actions/UpdateCompanyLogo.php, and models/CompanyDetails.php.
0
Attacker Value
Unknown
CVE-2018-18987
Disclosure Date: November 30, 2018 (last updated November 27, 2024)
VT-Designer Version 2.1.7.31 is vulnerable by the program populating objects with user supplied input via a file without first checking for validity, allowing attacker supplied input to be written to known memory locations. This may cause the program to crash or allow remote code execution.
0
Attacker Value
Unknown
CVE-2018-18983
Disclosure Date: November 30, 2018 (last updated November 27, 2024)
VT-Designer Version 2.1.7.31 is vulnerable by the program reading the contents of a file (which is already in memory) into another heap-based buffer, which may cause the program to crash or allow remote code execution.
0
Attacker Value
Unknown
CVE-2018-4022
Disclosure Date: October 26, 2018 (last updated November 27, 2024)
A use-after-free vulnerability exists in the way MKVToolNix MKVINFO v25.0.0 handles the MKV (matroska) file format. A specially crafted MKV file can cause arbitrary code execution in the context of the current user.
0
Attacker Value
Unknown
CVE-2018-13589
Disclosure Date: July 09, 2018 (last updated November 27, 2024)
The mintToken function of a smart contract implementation for MooAdvToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
0
Attacker Value
Unknown
CVE-2014-1226
Disclosure Date: April 06, 2018 (last updated November 26, 2024)
The pipe_init_terminal function in main.c in s3dvt allows local users to gain privileges by leveraging setuid permissions and usage of bash 4.3 and earlier. NOTE: This vulnerability exists because of an incomplete fix for CVE-2013-6876.
0