Show filters
27 Total Results
Displaying 1-10 of 27
Sort by:
Attacker Value
Unknown
CVE-2023-30738
Disclosure Date: October 04, 2023 (last updated October 09, 2023)
An improper input validation in UEFI Firmware prior to Firmware update Oct-2023 Release in Galaxy Book, Galaxy Book Pro, Galaxy Book Pro 360 and Galaxy Book Odyssey allows local attacker to execute SMM memory corruption.
0
Attacker Value
Unknown
CVE-2022-3792
Disclosure Date: December 19, 2022 (last updated December 22, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GullsEye GullsEye terminal operating system allows SQL Injection.This issue affects GullsEye terminal operating system: from unspecified before 5.0.13.
0
Attacker Value
Unknown
CVE-2021-43766
Disclosure Date: August 25, 2022 (last updated October 08, 2023)
Odyssey passes to server unencrypted bytes from man-in-the-middle When Odyssey is configured to use certificate Common Name for client authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This is similar to CVE-2021-23214 for PostgreSQL.
0
Attacker Value
Unknown
CVE-2022-26665
Disclosure Date: April 18, 2022 (last updated February 23, 2025)
An Insecure Direct Object Reference issue exists in the Tyler Odyssey Portal platform before 17.1.20. This may allow an external party to access sensitive case records.
0
Attacker Value
Unknown
CVE-2021-23663
Disclosure Date: December 10, 2021 (last updated February 23, 2025)
All versions of package sey are vulnerable to Prototype Pollution via the deepmerge() function.
0
Attacker Value
Unknown
CVE-2021-28168
Disclosure Date: April 22, 2021 (last updated February 22, 2025)
Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.
0
Attacker Value
Unknown
CVE-2021-3341
Disclosure Date: January 29, 2021 (last updated February 22, 2025)
A path traversal vulnerability in the DxWebEngine component of DH2i DxEnterprise and DxOdyssey for Windows, version 19.5 through 20.x before 20.0.219.0, allows an attacker to read any file on the host file system via an HTTP request.
0
Attacker Value
Unknown
CVE-2014-3643
Disclosure Date: December 15, 2019 (last updated November 27, 2024)
jersey: XXE via parameter entities not disabled by the jersey SAX parser
0
Attacker Value
Unknown
CVE-2017-9476
Disclosure Date: July 31, 2017 (last updated November 26, 2024)
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST); and Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG1682_2.2p7s2_PROD_sey) devices makes it easy for remote attackers to determine the hidden SSID and passphrase for a Home Security Wi-Fi network.
0
Attacker Value
Unknown
CVE-2017-9490
Disclosure Date: July 31, 2017 (last updated November 26, 2024)
The Comcast firmware on Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG1682_2.2p7s2_PROD_sey) devices allows configuration changes via CSRF.
0