CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Dir-825/ac_g1_firmware, Dir-825/ac_g1, Dsl-2875al_firmware, Dsl-2875al, Dsl-2877al_firmware, Dsl-2877al, Dap-1360_revision_f_firmware, Dap-1360_revision_f, Dsl-2680_firmware, Dsl-2680
2020-03-05
N/A
5.4 MEDIUM
A Stored XSS issue in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an authenticated attacker to inject arbitrary JavaScript code into the info.html administration page by sending a crafted Forms/wireless_autonetwork_1 POST request.
In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.
BMC Control-M/Agent 7.0.00.000 allows OS Command Injection (issue 2 of 2).
Sd-wan_firmware, Vedge-100, Vedge-1000, Vedge-100b, Vedge-2000, Vedge-5000, Vedge_100m, Vedge_100wm, Hyperflex_hx220c_m5_firmware, Hyperflex_hx220c_m5
2019-10-09
N/A
7.5 HIGH
A vulnerability in Cisco SIP IP Phone Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected phone. The vulnerability is due to insufficient validation of input Session Initiation Protocol (SIP) packets. An attacker could exploit this vulnerability by altering the SIP replies that are sent to the affected phone during the registration process. A successful exploit could allow the attacker to cause the phone to reboot and not complete the registration process.
BMC Control-M/Agent 7.0.00.000 allows Arbitrary File Download.
BMC Control-M/Agent 7.0.00.000 has Insecure Password Storage.
BMC Control-M/Agent 7.0.00.000 allows OS Command Injection.
BMC Control-M/Agent 7.0.00.000 has an Insecure File Copy.
A buffer overflow vulnerability in BMC Control-M/Agent 7.0.00.000 when the On-Do action destination is Mail and the Control-M/Agent is configured to send the email, allows remote attackers to have unspecified impact via vectors related to the configured IP address or SMTP server.
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue in customer-controlled software. Notes: none.
