CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122323053
In wpa_supplicant_8, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122465453
In wpa_supplicant_8, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122529021
In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122675483
Median_500l-msbr_firmware, Median_500l-msbr, Median_500-msbr_firmware, Median_500-msbr, Median_m800b-msbr_firmware, Median_m800b-msbr, Median_800c-msbr_firmware, Median_800c-msbr, Mediant_500l-msbr_firmware, Mediant_500l-msbr
2019-07-26
N/A
8.8 HIGH
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions before 7.20A.202.307. A Cross-Site Request Forgery (CSRF) vulnerability in the management web interface allows remote attackers to execute malicious and unauthorized actions, because CSRFProtection=1 is not a default and is not documented.
Median_500l-msbr_firmware, Median_500l-msbr, Median_500-msbr_firmware, Median_500-msbr, Median_m800b-msbr_firmware, Median_m800b-msbr, Median_800c-msbr_firmware, Median_800c-msbr, Mediant_500l-msbr_firmware, Mediant_500l-msbr
2019-07-29
N/A
6.1 MEDIUM
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.253. A cross-site scripting (XSS) vulnerability in the search function of the management web interface allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.
Median_500l-msbr_firmware, Median_500l-msbr, Median_500-msbr_firmware, Median_500-msbr, Median_m800b-msbr_firmware, Median_m800b-msbr, Median_800c-msbr_firmware, Median_800c-msbr, Mediant_500l-msbr_firmware, Mediant_500l-msbr
2020-08-24
N/A
8.8 HIGH
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An internal interface exposed to the link-local address 169.254.254.253 allows attackers in the local network to access multiple quagga VTYs. Attackers can authenticate with the default 1234 password that cannot be changed, and can execute malicious and unauthorized actions.
Median_500l-msbr_firmware, Median_500l-msbr, Median_500-msbr_firmware, Median_500-msbr, Median_m800b-msbr_firmware, Median_m800b-msbr, Median_800c-msbr_firmware, Median_800c-msbr, Mediant_500l-msbr_firmware, Mediant_500l-msbr
2020-08-24
N/A
7.5 HIGH
** DISPUTED ** An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A at least to 7.20A.252.062. The (1) management SSH and (2) management TELNET features allow remote attackers to cause a denial of service (connection slot exhaustion) via 5 unauthenticated connection attempts, because the maximum number of unauthenticated clients that can be configured is 5. NOTE: the vendor's position is that this is a "design choice."
An issue was discovered in baigo CMS 2.1.1. There is a vulnerability that allows remote attackers to execute arbitrary code. A BG_SITE_NAME parameter with malicious code can be written into the opt_base.inc.php file.
An issue was discovered in baigo CMS 2.1.1. There is a persistent XSS vulnerability that allows remote attackers to inject arbitrary web script or HTML via the opt[base][BG_SITE_NAME] parameter to the bg_console/index.php?m=opt&c=request URI.
