Show filters
200 Total Results
Displaying 91-100 of 200
Sort by:
Attacker Value
Unknown

CVE-2021-23851

Disclosure Date: May 20, 2021 (last updated February 23, 2025)
A specially crafted TCP/IP packet may cause the camera recovery image web interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with administrative rights or with physical access to the camera and allows the upload of a new firmware in case of a damaged firmware.
Attacker Value
Unknown

CVE-2021-23850

Disclosure Date: May 20, 2021 (last updated February 23, 2025)
A specially crafted TCP/IP packet may cause a camera recovery image telnet interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with administrative rights or with physical access to the camera and allows the upload of a new firmware in case of a damaged firmware.
Attacker Value
Unknown

CVE-2021-20515

Disclosure Date: April 29, 2021 (last updated February 22, 2025)
IBM Informix Dynamic Server 14.10 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local privileged user could overflow a buffer and execute arbitrary code on the system or cause a denial of service condition. IBM X-Force ID: 198366.
Attacker Value
Unknown

CVE-2021-31777

Disclosure Date: April 28, 2021 (last updated February 22, 2025)
The dce (aka Dynamic Content Element) extension 2.2.0 through 2.6.x before 2.6.2, and 2.7.x before 2.7.1, for TYPO3 allows SQL Injection via a backend user account.
Attacker Value
Unknown

CVE-2021-3327

Disclosure Date: March 19, 2021 (last updated February 22, 2025)
Ovation Dynamic Content 1.10.1 for Elementor allows XSS via the post_title parameter.
Attacker Value
Unknown

CVE-2020-27298

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live (Release 1.0), ViewForum (Release 6.3V1L10). The software constructs all or part of an OS command using externally influenced input from an upstream component but does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when sent to a downstream component.
Attacker Value
Unknown

CVE-2020-35463

Disclosure Date: December 15, 2020 (last updated February 22, 2025)
Version 1.0.0 of the Instana Dynamic APM Docker image contains a blank password for the root user. Systems deployed using affected versions of the Instana Dynamic APM container may allow a remote attacker to achieve root access with a blank password.
Attacker Value
Unknown

CVE-2020-12306

Disclosure Date: November 12, 2020 (last updated February 22, 2025)
Incorrect default permissions in the Intel(R) RealSense(TM) D400 Series Dynamic Calibration Tool before version 2.11, may allow an authenticated user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2020-12304

Disclosure Date: November 12, 2020 (last updated November 28, 2024)
Improper access control in Installer for Intel(R) DAL SDK before version 2.1 for Windows may allow an authenticated user to potentially enable escalation of privileges via local access.
Attacker Value
Unknown

CVE-2020-3598

Disclosure Date: October 07, 2020 (last updated February 22, 2025)
A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to access confidential information or make configuration changes. The vulnerability is due to missing authentication for a specific section of the web-based management interface. An attacker could exploit this vulnerability by accessing a crafted URL. A successful exploit could allow the attacker to obtain access to a section of the interface, which they could use to read confidential information or make configuration changes.