CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Sea_tel_coastal_18_firmware, Sea_tel_coastal_18, Sailor_600_vsat_ku_firmware, Sailor_600_vsat_ku, Sailor_800_vsat_firmware, Sailor_800_vsat, Sailor_900_vsat_firmware, Sailor_900_vsat, Sailor_900_vsat_high_power_firmware, Sailor_900_vsat_high_power
2019-09-18
N/A
5.3 MEDIUM
Cobham Sea Tel v170 224521 through v194 225444 devices allow attackers to obtain potentially sensitive information, such as a vessel's latitude and longitude, via the public SNMP community.
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected device. An attacker could exploit this vulnerability by persuading a user to follow a malicious link. A successful exploit could allow the attacker to use a web browser and the privileges of the user to perform arbitrary actions on the affected device.
In Wireshark 3.0.0 to 3.0.3 and 2.6.0 to 2.6.10, the Gryphon dissector could go into an infinite loop. This was addressed in plugins/epan/gryphon/packet-gryphon.c by checking for a message length of zero.
In Pimcore before 5.7.1, an attacker with limited privileges can bypass file-extension restrictions via a 256-character filename, as demonstrated by the failure of automatic renaming of .php to .php.txt for long filenames, a different vulnerability than CVE-2019-10867 and CVE-2019-16317.
In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a phar:// URL in a filename parameter, because PHAR uploads are not blocked and are reachable within the phar://../../../../../../../../var/www/html/web/var/assets/ directory, a different vulnerability than CVE-2019-10867 and CVE-2019-16318.
Indexhibit 2.1.5 allows a product reinstallation, with resultant remote code execution, via /ndxzstudio/install.php?p=2.
Fr6_firmware, Fr6, Fr8_firmware, Fr8, Fr5_firmware, Fr5, Fr5-e_firmware, Fr5-e, Fr6-s_firmware, Fr6-s
2020-08-24
N/A
7.5 HIGH
ifw8 Router ROM v4.31 allows credential disclosure by reading the action/usermanager.htm HTML source code.
s-cms V3.0 has XSS in index.php?type=text via the S_id parameter.
NIUSHOP V1.11 has CSRF via search_info to index.php.
NIUSHOP V1.11 has XSS via the index.php?s=/admin URI.
