Show filters
151 Total Results
Displaying 1-10 of 151
Sort by:
Attacker Value
Very High

CVE-2019-7256

Disclosure Date: July 02, 2019 (last updated August 14, 2024)
Linear eMerge E3-Series devices allow Command Injections.
Attacker Value
Very High

CVE-2019-7252

Disclosure Date: July 02, 2019 (last updated November 27, 2024)
Linear eMerge E3-Series devices have Default Credentials.
1
Attacker Value
Unknown

CVE-2024-9441

Disclosure Date: October 02, 2024 (last updated October 03, 2024)
The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands via the login_id parameter when invoking the forgot_password functionality over HTTP.
0
Attacker Value
Unknown

CVE-2024-38986

Disclosure Date: July 30, 2024 (last updated August 09, 2024)
Prototype Pollution in 75lb deep-merge 1.1.1 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via merge methods of lodash to merge objects.
Attacker Value
Unknown

CVE-2024-1839

Disclosure Date: June 26, 2024 (last updated June 27, 2024)
Intrado 911 Emergency Gateway login form is vulnerable to an unauthenticated blind time-based SQL injection, which may allow an unauthenticated remote attacker to execute malicious code, exfiltrate data, or manipulate the database.
0
Attacker Value
Unknown

CVE-2024-37301

Disclosure Date: June 11, 2024 (last updated June 12, 2024)
Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Versions 6.5.1 and prior are vulnerable to remote code execution via server-side template injection which, when executed as root, can result in full takeover of the affected system. As of time of publication, no patched version exists, nor have any known workarounds been disclosed.
0
Attacker Value
Unknown

CVE-2024-23914

Disclosure Date: May 03, 2024 (last updated May 03, 2024)
Use of Externally-Controlled Format String vulnerability in Merge DICOM Toolkit C/C++ on Windows. When MC_Open_Association() function is used to open DICOM Association and gets DICOM Application Context Name with illegal characters, it might result in an unhandled exception.
0
Attacker Value
Unknown

CVE-2024-23913

Disclosure Date: May 03, 2024 (last updated May 03, 2024)
Use of Out-of-range Pointer Offset vulnerability in Merge DICOM Toolkit C/C++ on Windows. When deprecated MC_XML_To_Message() function is used to read a malformed DICOM XML file, it might result in memory access violation.
0
Attacker Value
Unknown

CVE-2024-23912

Disclosure Date: May 03, 2024 (last updated May 03, 2024)
Out-of-bounds Read vulnerability in Merge DICOM Toolkit C/C++ on Windows. When MC_Open_File() function is used to read a malformed DICOM data, it might result in over-reading memory buffer and could cause memory access violation.
0
Attacker Value
Unknown

CVE-2024-20352

Disclosure Date: April 03, 2024 (last updated April 04, 2024)
A vulnerability in Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a directory traversal attack, which could allow the attacker to perform arbitrary actions on an affected device. This vulnerability is due to insufficient protections for the web UI of an affected system. An attacker could exploit this vulnerability by sending crafted requests to the web UI. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user, such as accessing password or log files or uploading and deleting existing files from the system.
0