Show filters
15 Total Results
Displaying 1-10 of 15
Sort by:
Attacker Value
Unknown

CVE-2024-22167

Disclosure Date: March 13, 2024 (last updated June 25, 2024)
A potential DLL hijacking vulnerability in the SanDisk PrivateAccess application for Windows that could lead to arbitrary code execution in the context of the system user. This vulnerability is only exploitable locally if an attacker has access to a copy of the user's vault or has already gained access into a user's system. This attack is limited to the system in context and cannot be propagated.
0
Attacker Value
Unknown

CVE-2023-22812

Disclosure Date: March 24, 2023 (last updated February 24, 2025)
SanDisk PrivateAccess versions prior to 6.4.9 support insecure TLS 1.0 and TLS 1.1 protocols which are susceptible to man-in-the-middle attacks thereby compromising confidentiality and integrity of data.
Attacker Value
Unknown

CVE-2021-36750

Disclosure Date: December 22, 2021 (last updated February 23, 2025)
ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names).
Attacker Value
Unknown

CVE-2020-27659

Disclosure Date: November 30, 2020 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Synology SafeAccess before 1.2.3-0234 allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) profile parameter.
Attacker Value
Unknown

CVE-2020-27660

Disclosure Date: November 30, 2020 (last updated February 22, 2025)
SQL injection vulnerability in request.cgi in Synology SafeAccess before 1.2.3-0234 allows remote attackers to execute arbitrary SQL commands via the domain parameter.
Attacker Value
Unknown

CVE-2017-16560

Disclosure Date: November 16, 2017 (last updated November 08, 2023)
SanDisk Secure Access 3.01 vault decrypts and copies encrypted files to a temporary folder, where they can remain indefinitely in certain situations, such as if the file is being edited when the user exits the application or if the application crashes.
0
Attacker Value
Unknown

CVE-2014-9207

Disclosure Date: March 14, 2015 (last updated October 05, 2023)
Untrusted search path vulnerability in CmnView.exe in CIMON CmnView 2.14.0.1 and 3.x before UltimateAccess 3.02 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
0
Attacker Value
Unknown

CVE-2013-4596

Disclosure Date: June 02, 2014 (last updated October 05, 2023)
The Node Access Keys module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permissions, which allows remote attackers to bypass access restrictions via a node listing.
0
Attacker Value
Unknown

CVE-2013-2123

Disclosure Date: August 28, 2013 (last updated October 05, 2023)
The Node access user reference module 6.x-3.x before 6.x-3.5 and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to content containing a user reference field when the author update/delete grants are enabled and the author's user account is deleted, which allows remote attackers to modify the content via unspecified vectors.
0
Attacker Value
Unknown

CVE-2010-2467

Disclosure Date: June 25, 2010 (last updated October 04, 2023)
The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not require setting a password for the FTP server that stores database backups, which makes it easier for remote attackers to download backup files via unspecified FTP requests.
0