Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2021-29929

Disclosure Date: April 01, 2021 (last updated February 22, 2025)
An issue was discovered in the endian_trait crate through 2021-01-04 for Rust. A double drop can occur when a user-provided Endian impl panics.
Attacker Value
Unknown

CVE-2021-27201

Disclosure Date: February 15, 2021 (last updated February 22, 2025)
Endian Firewall Community (aka EFW) 3.3.2 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in a backup comment.
Attacker Value
Unknown

CVE-2015-5082

Disclosure Date: September 28, 2015 (last updated October 05, 2023)
Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW_PASSWORD_1 or (2) NEW_PASSWORD_2 parameter to cgi-bin/chpasswd.cgi.
0
Attacker Value
Unknown

CVE-2012-4923

Disclosure Date: September 15, 2012 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Endian Firewall 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) createrule parameter to dnat.cgi, (2) addrule parameter to dansguardian.cgi, or (3) PATH_INFO to openvpn_users.cgi.
0
Attacker Value
Unknown

CVE-2008-0494

Disclosure Date: January 30, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in vpnum/userslist.php in Endian Firewall 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the psearch parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0