Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2019-15084

Disclosure Date: August 16, 2019 (last updated November 27, 2024)
Realtek Waves MaxxAudio driver 1.6.2.0, as used on Dell laptops, installs with incorrect file permissions. As a result, a local attacker can escalate to SYSTEM.
0
Attacker Value
Unknown

CVE-2019-13208

Disclosure Date: July 03, 2019 (last updated November 27, 2024)
WavesSysSvc in Waves MAXX Audio allows privilege escalation because the General registry key has Full Control access for the Users group, leading to DLL side loading. This affects WavesSysSvc64.exe 1.9.29.0.
0
Attacker Value
Unknown

CVE-2017-6005

Disclosure Date: July 26, 2017 (last updated November 26, 2024)
Waves MaxxAudio, as installed on Dell laptops, adds a "WavesSysSvc" Windows service with File Version 1.1.6.0. This service has a vulnerability known as Unquoted Service Path. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system.
0
Attacker Value
Unknown

CVE-2016-9357

Disclosure Date: February 13, 2017 (last updated November 26, 2024)
An issue was discovered in certain legacy Eaton ePDUs -- the affected products are past end-of-life (EoL) and no longer supported: EAMxxx prior to June 30, 2015, EMAxxx prior to January 31, 2014, EAMAxx prior to January 31, 2014, EMAAxx prior to January 31, 2014, and ESWAxx prior to January 31, 2014. An unauthenticated attacker may be able to access configuration files with a specially crafted URL (Path Traversal).
0
Attacker Value
Unknown

CVE-2012-4702

Disclosure Date: March 11, 2013 (last updated October 05, 2023)
360 Systems Maxx, Image Server Maxx, and Image Server 2000 have a hardcoded password for the root account, which makes it easier for remote attackers to execute arbitrary code, or modify video content or scheduling, via an SSH session.
0
Attacker Value
Unknown

CVE-2006-2258

Disclosure Date: May 09, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Logon.asp in MaxxSchedule 1.0 allows remote attackers to inject arbitrary web script or HTML via the Error parameter.
0
Attacker Value
Unknown

CVE-2006-2259

Disclosure Date: May 09, 2006 (last updated October 04, 2023)
SQL injection vulnerability in Logon.asp in MaxxSchedule 1.0 allows remote attackers to execute arbitrary SQL commands via the txtLogon parameter.
0