Show filters
15 Total Results
Displaying 1-10 of 15
Sort by:
Attacker Value
Unknown

CVE-2020-22159

Disclosure Date: July 18, 2023 (last updated October 08, 2023)
EVERTZ devices 3080IPX exe-guest-v1.2-r26125, 7801FC 1.3 Build 27, and 7890IXG V494 are vulnerable to Arbitrary File Upload, allowing an authenticated attacker to upload a webshell or overwrite any critical system files.
Attacker Value
Unknown

CVE-2022-43325

Disclosure Date: December 02, 2022 (last updated October 08, 2023)
An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MPX Node 1.3.* - 1.4.* allows attackers to execute arbitrary commands via a crafted payload injected into the license input.
Attacker Value
Unknown

CVE-2019-16649

Disclosure Date: September 21, 2019 (last updated November 27, 2024)
On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows capture of BMC credentials and data transferred over virtual media devices. Attackers can use captured credentials to connect virtual USB devices to the server managed by the BMC.
Attacker Value
Unknown

CVE-2019-16650

Disclosure Date: September 21, 2019 (last updated November 27, 2024)
On Supermicro X10 and X11 products, a client's access privileges may be transferred to a different client that later has the same socket file descriptor number. In opportunistic circumstances, an attacker can simply connect to the virtual media service, and then connect virtual USB devices to the server managed by the BMC.
Attacker Value
Unknown

CVE-2018-6876

Disclosure Date: February 09, 2018 (last updated November 26, 2024)
The OLEProperty class in ole/oleprop.cpp in libfpx 1.3.1-10, as used in ImageMagick 7.0.7-22 Q16 and other products, allows remote attackers to cause a denial of service (stack-based buffer under-read) via a crafted bmp image.
0
Attacker Value
Unknown

CVE-2017-12925

Disclosure Date: August 28, 2017 (last updated November 26, 2024)
Double free vulnerability in DfFromLB in docfile.cxx in libfpx 1.3.1_p6 allows remote attackers to cause a denial of service via a crafted fpx image.
0
Attacker Value
Unknown

CVE-2017-12924

Disclosure Date: August 28, 2017 (last updated November 26, 2024)
CDirVector::GetTable in dirfunc.hxx in libfpx 1.3.1_p6 allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted fpx image.
0
Attacker Value
Unknown

CVE-2017-12919

Disclosure Date: August 28, 2017 (last updated November 26, 2024)
Heap-based buffer overflow in OLEStream::WriteVT_LPSTR in olestrm.cpp in libfpx 1.3.1_p6 allows remote attackers to cause a denial of service via a crafted fpx image.
0
Attacker Value
Unknown

CVE-2017-12921

Disclosure Date: August 28, 2017 (last updated November 26, 2024)
PFileFlashPixView::GetGlobalInfoProperty in f_fpxvw.cpp in libfpx 1.3.1_p6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted fpx image.
0
Attacker Value
Unknown

CVE-2017-12922

Disclosure Date: August 28, 2017 (last updated November 26, 2024)
wchar.c in libfpx 1.3.1_p6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted fpx image.
0