• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2018-13313
A3002ru Firmware, Totolink
A3002ru_firmware, A3002ru, A702r_firmware, A702r, N302r_firmware, N302r, N300rt_firmware, N300rt, N200re_firmware, N200re
2020-03-04
N/A
6.5 MEDIUM
In TOTOLINK A3002RU 1.0.8, the router provides a page that allows the user to change their account name and password. This page, password.htm, contains JavaScript which is used to confirm the user knows their current password before allowing them to change their password. However, this JavaScript contains the current user’s password in plaintext.
CVE-2018-13312
A3002ru Firmware, Totolink
A3002ru_firmware, A3002ru, A702r_firmware, A702r, N302r_firmware, N302r, N300rt_firmware, N300rt, N200re_firmware, N200re
2018-12-19
N/A
6.1 MEDIUM
Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "Input your notice URL" field.
CVE-2018-13311
A3002ru Firmware, Totolink
A3002ru_firmware, A3002ru, A702r_firmware, A702r, N302r_firmware, N302r, N300rt_firmware, N300rt, N200re_firmware, N200re
2019-10-03
N/A
9.8 CRITICAL
System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "sambaUser" POST parameter.
CVE-2018-13310
A3002ru Firmware, Totolink
A3002ru_firmware, A3002ru, A702r_firmware, A702r, N302r_firmware, N302r, N300rt_firmware, N300rt, N200re_firmware, N200re
2018-12-19
N/A
6.1 MEDIUM
Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's username.
CVE-2018-1331
2019-10-03
N/A
8.8 HIGH
In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a secure storm cluster in some cases could execute arbitrary code as a different user.
CVE-2018-13309
A3002ru Firmware, Totolink
A3002ru_firmware, A3002ru, A702r_firmware, A702r, N302r_firmware, N302r, N300rt_firmware, N300rt, N200re_firmware, N200re
2018-12-19
N/A
6.1 MEDIUM
Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's password.
CVE-2018-13308
A3002ru Firmware, Totolink
A3002ru_firmware, A3002ru, A702r_firmware, A702r, N302r_firmware, N302r, N300rt_firmware, N300rt, N200re_firmware, N200re
2018-12-19
N/A
6.1 MEDIUM
Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "User phrases button" field.
CVE-2018-13307
A3002ru Firmware, Totolink
A3002ru_firmware, A3002ru, A702r_firmware, A702r, N302r_firmware, N302r, N300rt_firmware, N300rt, N200re_firmware, N200re
2019-10-03
N/A
9.8 CRITICAL
System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ntpServerIp2" POST parameter. Certain payloads cause the device to become permanently inoperable.
CVE-2018-13306
A3002ru Firmware, Totolink
A3002ru_firmware, A3002ru, A702r_firmware, A702r, N302r_firmware, N302r, N300rt_firmware, N300rt, N200re_firmware, N200re
2019-10-03
N/A
9.8 CRITICAL
System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ftpUser" POST parameter.
CVE-2018-13305
2020-01-14
N/A
8.1 HIGH
In FFmpeg 4.0.1, due to a missing check for negative values of the mquant variable, the vc1_put_blocks_clamped function in libavcodec/vc1_block.c may trigger an out-of-array access while converting a crafted AVI file to MPEG4, leading to an information disclosure or a denial of service.
« Previous 1 … 2,614 2,615 2,616 2,617 2,618 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE