Show filters
110 Total Results
Displaying 91-100 of 110
Sort by:
Attacker Value
Unknown
CVE-2020-11448
Disclosure Date: November 17, 2023 (last updated November 25, 2023)
An issue was discovered on Bell HomeHub 3000 SG48222070 devices. There is XSS related to the email field and the login page.
0
Attacker Value
Unknown
CVE-2020-11447
Disclosure Date: November 17, 2023 (last updated November 25, 2023)
An issue was discovered on Bell HomeHub 3000 SG48222070 devices. Remote authenticated users can retrieve the serial number via cgi/json-req - this is an information leak because the serial number is intended to prove an actor's physical access to the device.
0
Attacker Value
Unknown
CVE-2023-0321
Disclosure Date: January 17, 2023 (last updated February 24, 2025)
Campbell Scientific dataloggers CR6, CR300, CR800, CR1000 and CR3000 may allow an attacker to download configuration files, which may contain sensitive information about the internal network. From factory defaults, the mentioned datalogges have HTTP and PakBus enabled. The devices, with the default configuration, allow this situation via the PakBus port. The exploitation of this vulnerability may allow an attacker to download, modify, and upload new configuration files.
0
Attacker Value
Unknown
CVE-2019-13336
Disclosure Date: October 08, 2019 (last updated November 27, 2024)
The dbell Wi-Fi Smart Video Doorbell DB01-S Gen 1 allows remote attackers to launch commands with no authentication verification via TCP port 81, because the loginuse and loginpass parameters to openlock.cgi can have arbitrary values. NOTE: the vendor's position is that this product reached end of life in 2016.
0
Attacker Value
Unknown
CVE-2018-0544
Disclosure Date: March 09, 2018 (last updated November 26, 2024)
Untrusted search path vulnerability in WinShot 1.53a and earlier (Installer) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
0
Attacker Value
Unknown
CVE-2018-0543
Disclosure Date: March 09, 2018 (last updated November 26, 2024)
Untrusted search path vulnerability in Jtrim 1.53c and earlier (Installer) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
0
Attacker Value
Unknown
CVE-2014-7513
Disclosure Date: October 20, 2014 (last updated October 05, 2023)
The Top Hangover Cures (aka com.TopHangoverCures) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-7417
Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Real Academia de Bellas Artes (aka com.adianteventures.adianteapps.real_academia_de_bellas_artes) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-7108
Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Stop Headaches and Migraines (aka com.StopHeadachesandMigraines) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-6646
Disclosure Date: September 23, 2014 (last updated October 05, 2023)
The bellyhoodcom (aka com.tapatalk.bellyhoodcom) application 3.4.23 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0