• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-9541
2021-10-26
N/A
6.1 MEDIUM
: Information Exposure vulnerability in itemlookup.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5.
CVE-2019-9540
2020-01-06
N/A
6.1 MEDIUM
: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in prefs.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5.
CVE-2019-9539
2020-01-06
N/A
6.1 MEDIUM
: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ModalWindowPopup.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5.
CVE-2019-9538
2020-01-06
N/A
6.1 MEDIUM
: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the LDAP cbURL parameter of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5.
CVE-2019-9537
2020-01-06
N/A
6.1 MEDIUM
: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uploaditem.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5.
CVE-2019-9536
2021-07-21
N/A
6.8 MEDIUM
Apple iPhone 3GS bootrom malloc implementation returns a non-NULL pointer when unable to allocate memory, aka 'alloc8'. An attacker with physical access to the device can install arbitrary firmware.
CVE-2019-9535
2021-10-26
N/A
9.8 CRITICAL
A vulnerability exists in the way that iTerm2 integrates with tmux's control mode, which may allow an attacker to execute arbitrary commands by providing malicious output to the terminal. This affects versions of iTerm2 up to and including 3.3.5. This vulnerability may allow an attacker to execute arbitrary commands on their victim's computer by providing malicious output to the terminal. It could be exploited using command-line utilities that print attacker-controlled content.
CVE-2019-9534
Cobham, Explorer 710, Explorer 710 Firmware
Sea_tel_coastal_18_firmware, Sea_tel_coastal_18, Sailor_600_vsat_ku_firmware, Sailor_600_vsat_ku, Sailor_800_vsat_firmware, Sailor_800_vsat, Sailor_900_vsat_firmware, Sailor_900_vsat, Sailor_900_vsat_high_power_firmware, Sailor_900_vsat_high_power
2019-10-16
N/A
7.8 HIGH
The Cobham EXPLORER 710, firmware version 1.07, does not validate its firmware image. Development scripts left in the firmware can be used to upload a custom firmware image that the device runs. This could allow an unauthenticated, local attacker to upload their own firmware that could be used to intercept or modify traffic, spoof or intercept GPS traffic, exfiltrate private data, hide a backdoor, or cause a denial-of-service.
CVE-2019-9533
Cobham, Explorer 710, Explorer 710 Firmware
Sea_tel_coastal_18_firmware, Sea_tel_coastal_18, Sailor_600_vsat_ku_firmware, Sailor_600_vsat_ku, Sailor_800_vsat_firmware, Sailor_800_vsat, Sailor_900_vsat_firmware, Sailor_900_vsat, Sailor_900_vsat_high_power_firmware, Sailor_900_vsat_high_power
2020-10-16
N/A
9.8 CRITICAL
The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08. This could allow an attacker to reverse-engineer the password from available versions to gain authenticated access to the device.
CVE-2019-9532
Cobham, Explorer 710, Explorer 710 Firmware
Sea_tel_coastal_18_firmware, Sea_tel_coastal_18, Sailor_600_vsat_ku_firmware, Sailor_600_vsat_ku, Sailor_800_vsat_firmware, Sailor_800_vsat, Sailor_900_vsat_firmware, Sailor_900_vsat, Sailor_900_vsat_high_power_firmware, Sailor_900_vsat_high_power
2019-10-17
N/A
7.8 HIGH
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, sends the login password in cleartext. This could allow an unauthenticated, local attacker to intercept the password and gain access to the portal.
« Previous 1 … 5,081 5,082 5,083 5,084 5,085 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE