Show filters
21 Total Results
Displaying 1-10 of 21
Sort by:
Attacker Value
Unknown

CVE-2022-28381

Disclosure Date: April 03, 2022 (last updated October 07, 2023)
Mediaserver.exe in ALLMediaServer 1.6 has a stack-based buffer overflow that allows remote attackers to execute arbitrary code via a long string to TCP port 888, a related issue to CVE-2017-17932.
Attacker Value
Unknown

CVE-2022-28480

Disclosure Date: April 29, 2022 (last updated October 07, 2023)
ALLMediaServer 1.6 is vulnerable to Buffer Overflow via MediaServer.exe.
Attacker Value
Unknown

CVE-2021-42109

Disclosure Date: October 08, 2021 (last updated November 28, 2024)
VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root.
Attacker Value
Unknown

CVE-2019-17091

Disclosure Date: October 02, 2019 (last updated November 27, 2024)
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.
Attacker Value
Unknown

CVE-2017-16142

Disclosure Date: June 07, 2018 (last updated November 26, 2024)
infraserver is a RESTful server. infraserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
0
Attacker Value
Unknown

CVE-2017-16170

Disclosure Date: June 07, 2018 (last updated November 26, 2024)
liuyaserver is a static file server. liuyaserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
0
Attacker Value
Unknown

CVE-2017-17932

Disclosure Date: December 28, 2017 (last updated November 26, 2024)
A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow remote attackers to execute arbitrary code and/or cause denial of service on the victim machine/computer via a long string to TCP port 888.
0
Attacker Value
Unknown

CVE-2012-4340

Disclosure Date: August 15, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Sybase EAServer before 6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-3007

Disclosure Date: July 05, 2012 (last updated October 04, 2023)
Stack-based buffer overflow in slssvc.exe before 58.x in Invensys Wonderware SuiteLink in the Invensys System Platform software suite, as used in InTouch/Wonderware Application Server IT before 10.5 and WAS before 3.5, DASABCIP before 4.1 SP2, DASSiDirect before 3.0, DAServer Runtime Components before 3.0 SP2, and other products, allows remote attackers to cause a denial of service (daemon crash or hang) via a long Unicode string.
0
Attacker Value
Unknown

CVE-2011-2474

Disclosure Date: June 09, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in the HTTP Server in Sybase EAServer 6.3.1 Developer Edition allows remote attackers to read arbitrary files via a /.\../\../\ sequence in a path.
0