Show filters
27 Total Results
Displaying 1-10 of 27
Sort by:
Attacker Value
Unknown

CVE-2023-0750

Disclosure Date: April 06, 2023 (last updated November 08, 2023)
Yellobrik PEC-1864 implements authentication checks via javascript in the frontend interface.  When the device can be accessed over the network an attacker could bypass authentication. This would allow an attacker to : - Change the password, resulting in a DOS of the users - Change the streaming source, compromising the integrity of the stream - Change the streaming destination, compromising the confidentiality of the stream This issue affects Yellowbrik: PEC 1864. No patch has been issued by the manufacturer as this model was discontinued.
Attacker Value
Unknown

CVE-2021-38165

Disclosure Date: August 07, 2021 (last updated February 23, 2025)
Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.
Attacker Value
Unknown

CVE-2018-9177

Disclosure Date: June 08, 2018 (last updated November 26, 2024)
Twonky Server before 8.5.1 has XSS via a folder name on the Shared Folders screen.
0
Attacker Value
Unknown

CVE-2018-9182

Disclosure Date: June 08, 2018 (last updated November 26, 2024)
Twonky Server before 8.5.1 has XSS via a modified "language" parameter in the Language section.
0
Attacker Value
Unknown

CVE-2018-7171

Disclosure Date: March 30, 2018 (last updated November 26, 2024)
Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of arbitrary directories via a .. (dot dot) in the contentbase parameter to rpc/set_all.
0
Attacker Value
Unknown

CVE-2018-7203

Disclosure Date: March 30, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to inject arbitrary web script or HTML via the friendlyname parameter to rpc/set_all.
0
Attacker Value
Unknown

CVE-2014-5002

Disclosure Date: January 10, 2018 (last updated November 26, 2024)
The lynx gem before 1.0.0 for Ruby places the configured password on command lines, which allows local users to obtain sensitive information by listing processes.
0
Attacker Value
Unknown

CVE-2017-1000211

Disclosure Date: November 17, 2017 (last updated November 26, 2024)
Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.
0
Attacker Value
Unknown

CVE-2016-8357

Disclosure Date: February 13, 2017 (last updated November 26, 2024)
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. A user with read-only access can send commands to the software and the application will accept those commands. This would allow an attacker with read-only access to make changes within the application.
0
Attacker Value
Unknown

CVE-2016-8378

Disclosure Date: February 13, 2017 (last updated November 26, 2024)
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application's database lacks sufficient safeguards for protecting credentials.
0