CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function uploadPicture. This vulnerability allows attackers to execute arbitrary commands via the pic_name parameter.
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function guestWifiRuleRefresh. This vulnerability allows attackers to cause a Denial of Service (DoS) via the qosGuestUpstream and qosGuestDownstream parameters.
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formAddDnsForward. This vulnerability allows attackers to cause a Denial of Service (DoS) via the DnsForwardRule parameter.
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetNetCheckTools. This vulnerability allows attackers to execute arbitrary commands via the hostName parameter.
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetUSBShareInfo. This vulnerability allows attackers to execute arbitrary commands via the usbOrdinaryUserName parameter.
Airmagnet_enterprise, Cdm_agent_firmware_maintenance_release, Ngenius_client, Ngenius_express_appliance, Ngenius_flow_recorder, Ngenius_infinistream, Ngeniusone, Ngenius_performance_manager, Ngenius_probes, Ngenius_trace_analyzer_integrator
2022-06-13
N/A
9.8 CRITICAL
NetScout nGeniusONE 6.3.2 allows Java RMI Code Execution.
NetScout nGeniusONE 6.3.2 allows Arbitrary File Upload by a privileged user.
Airmagnet_enterprise, Cdm_agent_firmware_maintenance_release, Ngenius_client, Ngenius_express_appliance, Ngenius_flow_recorder, Ngenius_infinistream, Ngeniusone, Ngenius_performance_manager, Ngenius_probes, Ngenius_trace_analyzer_integrator
2022-06-13
N/A
9.8 CRITICAL
NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack.
Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via getURL in the JavaScript API.
Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via app.launchURL in the JavaScript API.
