Unknown · CVSS Not scored
Heap-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a levels header.
Published Jan 2, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Heap-based buffer overflow in xnview.exe in XnView before 2.13 allows remote attackers to execute arbitrary code via the biBitCount field in a BMP file.
Published Jan 2, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple cross-site scripting (XSS) vulnerabilities in Opsview before 4.4.1 and Opsview Core before 20130522 allow remote attackers to inject arbitrary web script or HTML.
Published Jan 2, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code via (1) the Csiz parameter in a SIZ marker, which triggers an incorrect memory allocation, or (2) the lqcd field in a QCD marker in a crafted JPEG2000 file, which leads to a heap-based buffer overflow.
Published Jan 2, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Stack-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via an IMAGE tag.
Published Jan 2, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
xnview.exe in XnView before 2.13 does not properly handle RLE strip lengths during processing of RGB files, which allows remote attackers to execute arbitrary code via the RLE strip size field in a RGB file, which leads to an unexpected sign extension error and a heap-based buffer overflow.
Published Jan 2, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a nband tag.
Published Jan 2, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in the Jomres (com_jomres) component before 7.3.1 for Joomla! allows remote authenticated users with the "Business Manager" permission to inject arbitrary web script or HTML via the property_name parameter, related to editing property details.
Published Jan 2, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
SQL injection vulnerability in the Jomres (com_jomres) component before 7.3.1 for Joomla! allows remote authenticated users with the "Business Manager" permission to execute arbitrary SQL commands via the id parameter in an editProfile action to administrator/index.php.
Published Jan 2, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.1 and Opsview Core before 20130522 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via unspecified vectors.
Published Jan 2, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in the Hyperion Strategic Finance component in Oracle Hyperion 11.1.2.1 and 11.1.2.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Server.
Published Jan 15, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The image creation configuration in aaa_base before 16.26.1 for openSUSE 13.1 KDE adds the root user to the "users" group when installing from a live image, which allows local users to obtain sensitive information and possibly have other unspecified impacts, as demonstrated by reading /etc/shadow.
Published Jan 11, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (SMT_X9_315) and firmware for Supermicro X8 generation motherboards before SMT X8 312.
Published Jan 2, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The login page in the GoAhead web server on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches allows remote attackers to cause a denial of service (device outage) via a long username.
Published Jan 20, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The SSH service on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches allows remote attackers to cause a denial of service (device reset) or possibly execute arbitrary code by sending many packets to TCP port 22.
Published Jan 20, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon.
Published Jan 2, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The OpenManage web application 2.5 build 1.19 on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches allows remote authenticated users to cause a denial of service (device reset) via a direct request to an unspecified OSPF URL.
Published Jan 20, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
XnView 2.03 has an integer overflow vulnerability
Published Jan 27, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple cross-site scripting (XSS) vulnerabilities in the HTTP Interface in VideoLAN VLC Media Player before 2.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) command parameter to requests/vlm_cmd.xml, (2) dir parameter to requests/browse.xml, or (3) URI in a request, which is returned in an error message through share/lua/intf/http.lua.
Published Jan 31, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
XnView 2.03 has a stack-based buffer overflow vulnerability
Published Jan 27, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Stack-based buffer overflow in the rf_report_error function in ermapper_u.dll in Intergraph ERDAS ER Viewer before 13.0.1.1301 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long string in an ERS file.
Published Jan 19, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Buffer overflow in Media Player Classic - Home Cinema (MPC-HC) before 1.7.0 allows remote attackers to execute arbitrary code via a crafted RealMedia .rm file
Published Jan 31, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Stack-based buffer overflow in Media Player Classic - Home Cinema (MPC-HC) before 1.7.0.7858 allows remote attackers to execute arbitrary code via a crafted MPEG-2 Transport Stream (M2TS) file.
Published Jan 31, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IrfanView FlashPix Plugin 4.3.4 0 has an Integer Overflow Vulnerability
Published Jan 27, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Stack-based buffer overflow in ermapper_u.dll in Intergraph ERDAS ER Viewer before 13.0.1.1301 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ERS file.
Published Jan 19, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg".
Published Jan 29, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site Scripting (XSS) vulnerability in NetApp OnCommand System Manager before 2.2 allows remote attackers to inject arbitrary web script or HTML via the 'full-name' and 'comment' fields.
Published Jan 29, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to inject arbitrary commands in the Halt/Reboot interface.
Published Jan 31, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to include arbitrary files through specially crafted requests to the "diagnostic" page using the SnapMirror log path parameter.
Published Jan 29, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key.
Published Jan 29, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.
Published Jan 29, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execute local script code.
Published Jan 28, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Stack-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted image layer in an XCF file.
Published Jan 2, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
Published Jan 28, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Heap-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted RLE compressed layer in an XCF file.
Published Jan 2, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple cross-site scripting (XSS) vulnerabilities in Belkin N900 router allow remote attackers to inject arbitrary web script or HTML via the (1) ssid2 parameter to wl_channel.html or (2) guest_psk parameter to wl_guest.html.
Published Jan 30, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple cross-site scripting (XSS) vulnerabilities in Belkin N300 router allow remote attackers to inject arbitrary web script or HTML via the Guest Access PSK field to wireless_guest2_print.stm or other unspecified vectors.
Published Jan 30, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
ASUS RT-N56U devices allow CSRF.
Published Jan 28, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple cross-site scripting (XSS) vulnerabilities in Belkin Model F5D8236-4 v2 router allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published Jan 30, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass.
Published Jan 28, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
NetGear WNDR4700 Media Server devices with firmware 1.0.0.34 allow remote attackers to cause a denial of service (device crash).
Published Jan 28, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The BIRT viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.1.x before 7.2.1.5 allows remote authenticated users to bypass authorization checks and obtain report-administration privileges, and consequently create or delete reports or conduct SQL injection attacks, via crafted parameters to the BIRT reporting URL.
Published Jan 29, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 perform authentication on the KAEClientManager console rather than on the server, which allows remote attackers to bypass intended access restrictions and discover credentials via a crafted packet to TCP port 8130.
Published Jan 15, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Sierra Wireless AirLink Raven X EV-DO gateway 4221_4.0.11.003 and 4228_4.0.11.003 allows remote attackers to reprogram the firmware via a replay attack using UDP ports 17336 and 17388.
Published Jan 15, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 allows remote attackers to download arbitrary DLL code onto a client machine and execute this code via the ProjectURL property value.
Published Jan 15, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Sierra Wireless AirLink Raven X EV-DO gateway 4221_4.0.11.003 and 4228_4.0.11.003 allows remote attackers to install Trojan horse firmware by leveraging cleartext credentials in a crafted (1) update or (2) reprogramming action.
Published Jan 15, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system.
Published Jan 28, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Secure Entry Server before 4.7.0 contains a URI Redirection vulnerability which could allow remote attackers to conduct phishing attacks due to HSP_AbsoluteRedirects being disabled by default.
Published Jan 28, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in e107_plugins/content/handlers/content_preset.php in e107 before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the query string.
Published Jan 22, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Nitro PDF 8.5.0.26: A specially crafted DLL file can facilitate Arbitrary Code Execution
Published Jan 14, 2020 · Updated Aug 6, 2024