Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2019-14712

Disclosure Date: October 23, 2020 (last updated November 28, 2024)
Verifone VerixV Pinpad Payment Terminals with QT000530 allow bypass of integrity and origin control for S1G file generation.
Attacker Value
Unknown

CVE-2019-14713

Disclosure Date: October 23, 2020 (last updated November 28, 2024)
Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow installation of unsigned packages.
Attacker Value
Unknown

CVE-2019-14711

Disclosure Date: October 23, 2020 (last updated February 22, 2025)
Verifone MX900 series Pinpad Payment Terminals with OS 30251000 have a race condition for RBAC bypass.
Attacker Value
Unknown

CVE-2019-14719

Disclosure Date: October 23, 2020 (last updated February 22, 2025)
Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow multiple arbitrary command injections, as demonstrated by the file manager.
Attacker Value
Unknown

CVE-2019-14718

Disclosure Date: October 23, 2020 (last updated February 22, 2025)
Verifone MX900 series Pinpad Payment Terminals with OS 30251000 have Insecure Permissions, with resultant svc_netcontrol arbitrary command injection and privilege escalation.
Attacker Value
Unknown

CVE-2019-14715

Disclosure Date: October 23, 2020 (last updated February 22, 2025)
Verifone Pinpad Payment Terminals allow undocumented physical access to the system via an SBI bootloader memory write operation.
Attacker Value
Unknown

CVE-2019-14717

Disclosure Date: October 23, 2020 (last updated February 22, 2025)
Verifone Verix OS on VerixV Pinpad Payment Terminals with QT000530 have a Buffer Overflow via the Run system call.
Attacker Value
Unknown

CVE-2019-14716

Disclosure Date: October 23, 2020 (last updated November 28, 2024)
Verifone VerixV Pinpad Payment Terminals with QT000530 have an undocumented physical access mode (aka VerixV shell.out).
Attacker Value
Unknown

CVE-2019-10060

Disclosure Date: March 26, 2019 (last updated November 27, 2024)
The Verix Multi-app Conductor application 2.7 for Verifone Verix suffers from a buffer overflow vulnerability that allows attackers to execute arbitrary code via a long configuration key value. An attacker must be able to download files to the device in order to exploit this vulnerability.
0
Attacker Value
Unknown

CVE-2012-4951

Disclosure Date: November 15, 2012 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in terminal/paramedit.aspx in VeriFone VeriCentre Web Console before 2.2 build 36 allow remote attackers to execute arbitrary SQL commands via the (1) TerminalId, (2) ModelName, or (3) ApplicationName parameter.
0