Show filters
22 Total Results
Displaying 1-10 of 22
Sort by:
Attacker Value
Unknown
CVE-2024-8655
Disclosure Date: September 10, 2024 (last updated September 11, 2024)
A vulnerability was found in Mercury MNVR816 up to 2.0.1.0.5. It has been classified as problematic. This affects an unknown part of the file /web-static/. The manipulation leads to files or directories accessible. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2023-46518
Disclosure Date: October 25, 2023 (last updated November 02, 2023)
Mercury A15 V1.0 20230818_1.0.3 was discovered to contain a command execution vulnerability via the component cloudDeviceTokenSuccCB.
0
Attacker Value
Unknown
CVE-2021-27825
Disclosure Date: May 29, 2023 (last updated October 08, 2023)
A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-static/ URL.
0
Attacker Value
Unknown
CVE-2022-31517
Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The HolgerGraef/MSM repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
0
Attacker Value
Unknown
CVE-2022-31849
Disclosure Date: June 16, 2022 (last updated October 07, 2023)
MERCURY MIPC451-4 1.0.22 Build 220105 Rel.55642n was discovered to contain a remote code execution (RCE) vulnerability which is exploitable via a crafted POST request.
0
Attacker Value
Unknown
CVE-2020-22724
Disclosure Date: October 14, 2021 (last updated February 23, 2025)
A remote command execution vulnerability exists in add_server_service of PPTP_SERVER in Mercury Router MER1200 v1.0.1 and Mercury Router MER1200G v1.0.1.
0
Attacker Value
Unknown
CVE-2012-4999
Disclosure Date: September 19, 2012 (last updated October 05, 2023)
Mercury MR804 Router 8.0 3.8.1 Build 101220 Rel.53006nB allows remote attackers to cause a denial of service (service hang) via a crafted string in HTTP header fields such as (1) If-Modified-Since, (2) If-None-Match, or (3) If-Unmodified-Since. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2009-4755
Disclosure Date: March 29, 2010 (last updated October 04, 2023)
Multiple stack-based buffer overflows in Mercury Audio Player 1.21 allow remote attackers to execute arbitrary code via a long string in a malformed (1) .b4s or (2) .pls playlist file.
0
Attacker Value
Unknown
CVE-2009-4754
Disclosure Date: March 29, 2010 (last updated October 04, 2023)
Stack-based buffer overflow in Mercury Audio Player 1.21 allows remote attackers to execute arbitrary code via a long string in a malformed playlist (.m3u) file.
0
Attacker Value
Unknown
CVE-2008-7011
Disclosure Date: August 19, 2009 (last updated October 04, 2023)
The Unreal engine, as used in Unreal Tournament 3 1.3, Unreal Tournament 2003 and 2004, Dead Man's Hand, Pariah, WarPath, Postal2, and Shadow Ops, allows remote authenticated users to cause a denial of service (server exit) via multiple file downloads from the server, which triggers an assertion failure when the Closing flag in UnChan.cpp is set.
0