Export limit exceeded: 16030 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 16030 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 16030 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (16030 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-10703 1 Moxa 2 Awk-3121, Awk-3121 Firmware 2024-11-21 N/A
An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run scripts on the device to troubleshoot any issues. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "iw_serverip" is susceptible to buffer overflow. By crafting a packet that contains a string of 480 characters, it is possible for an attacker to execute the attack.
CVE-2018-10702 1 Moxa 2 Awk-3121, Awk-3121 Firmware 2024-11-21 8.8 High
An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run scripts on the device to troubleshoot any issues. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "iw_filename" is susceptible to command injection via shell metacharacters.
CVE-2018-10701 1 Moxa 2 Awk-3121, Awk-3121 Firmware 2024-11-21 N/A
An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run scripts on the device to troubleshoot any issues. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "iw_filename" is susceptible to buffer overflow. By crafting a packet that contains a string of 162 characters, it is possible for an attacker to execute the attack.
CVE-2018-10700 1 Moxa 2 Awk-3121, Awk-3121 Firmware 2024-11-21 N/A
An issue was discovered on Moxa AWK-3121 1.19 devices. It provides functionality so that an administrator can change the name of the device. However, the same functionality allows an attacker to execute XSS by injecting an XSS payload. The POST parameter "iw_board_deviceName" is susceptible to this injection.
CVE-2018-10699 1 Moxa 2 Awk-3121, Awk-3121 Firmware 2024-11-21 N/A
An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides certfile upload functionality so that an administrator can upload a certificate file used for connecting to the wireless network. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "iw_privatePass" is susceptible to this injection. By crafting a packet that contains shell metacharacters, it is possible for an attacker to execute the attack.
CVE-2018-10698 1 Moxa 2 Awk-3121, Awk-3121 Firmware 2024-11-21 9.8 Critical
An issue was discovered on Moxa AWK-3121 1.14 devices. The device enables an unencrypted TELNET service by default. This allows an attacker who has been able to gain an MITM position to easily sniff the traffic between the device and the user. Also an attacker can easily connect to the TELNET daemon using the default credentials if they have not been changed by the user.
CVE-2018-10697 1 Moxa 2 Awk-3121, Awk-3121 Firmware 2024-11-21 8.8 High
An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides ping functionality so that an administrator can execute ICMP calls to check if the network is working correctly. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "srvName" is susceptible to this injection. By crafting a packet that contains shell metacharacters, it is possible for an attacker to execute the attack.
CVE-2018-10696 1 Moxa 2 Awk-3121, Awk-3121 Firmware 2024-11-21 N/A
An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a web interface to allow an administrator to manage the device. However, this interface is not protected against CSRF attacks, which allows an attacker to trick an administrator into executing actions without his/her knowledge, as demonstrated by the forms/iw_webSetParameters and forms/webSetMainRestart URIs.
CVE-2018-10695 1 Moxa 2 Awk-3121, Awk-3121 Firmware 2024-11-21 N/A
An issue was discovered on Moxa AWK-3121 1.14 devices. It provides alert functionality so that an administrator can send emails to his/her account when there are changes to the device's network. However, the same functionality allows an attacker to execute commands on the device. The POST parameters "to1,to2,to3,to4" are all susceptible to buffer overflow. By crafting a packet that contains a string of 678 characters, it is possible for an attacker to execute the attack.
CVE-2018-10693 1 Moxa 2 Awk-3121, Awk-3121 Firmware 2024-11-21 N/A
An issue was discovered on Moxa AWK-3121 1.14 devices. It provides ping functionality so that an administrator can execute ICMP calls to check if the network is working correctly. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "srvName" is susceptible to a buffer overflow. By crafting a packet that contains a string of 516 characters, it is possible for an attacker to execute the attack.
CVE-2018-10692 1 Moxa 2 Awk-3121, Awk-3121 Firmware 2024-11-21 N/A
An issue was discovered on Moxa AWK-3121 1.14 devices. The session cookie "Password508" does not have an HttpOnly flag. This allows an attacker who is able to execute a cross-site scripting attack to steal the cookie very easily.
CVE-2018-10691 1 Moxa 2 Awk-3121, Awk-3121 Firmware 2024-11-21 N/A
An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /systemlog.log (the system log). However, the same functionality allows an attacker to download the file without any authentication or authorization.
CVE-2018-10689 2 Blktrace Project, Redhat 2 Blktrace, Enterprise Linux 2024-11-21 N/A
blktrace (aka Block IO Tracing) 1.2.0, as used with the Linux kernel and Android, has a buffer overflow in the dev_map_read function in btt/devmap.c because the device and devno arrays are too small, as demonstrated by an invalid free when using the btt program with a crafted file.
CVE-2018-10632 1 Moxa 6 Nport 5210, Nport 5210 Firmware, Nport 5230 and 3 more 2024-11-21 N/A
In Moxa NPort 5210, 5230, and 5232 versions 2.9 build 17030709 and prior, the amount of resources requested by a malicious actor are not restricted, allowing for a denial-of-service condition.
CVE-2018-10299 1 Beauty 1 Beauty Ecosystem Coin 2024-11-21 N/A
An integer overflow in the batchTransfer function of a smart contract implementation for Beauty Ecosystem Coin (BEC), the Ethereum ERC20 token used in the Beauty Chain economic system, allows attackers to accomplish an unauthorized increase of digital assets by providing two _receivers arguments in conjunction with a large _value argument, as exploited in the wild in April 2018, aka the "batchOverflow" issue.
CVE-2018-10196 3 Canonical, Fedoraproject, Graphviz 3 Ubuntu Linux, Fedora, Graphviz 2024-11-21 N/A
NULL pointer dereference vulnerability in the rebuild_vlists function in lib/dotgen/conc.c in the dotgen library in Graphviz 2.40.1 allows remote attackers to cause a denial of service (application crash) via a crafted file.
CVE-2018-10125 1 Contao 1 Contao 2024-11-21 6.1 Medium
Contao before 4.5.7 has XSS in the system log.
CVE-2018-10102 2 Debian, Wordpress 2 Debian Linux, Wordpress 2024-11-21 N/A
Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a generator tag.
CVE-2018-10101 2 Debian, Wordpress 2 Debian Linux, Wordpress 2024-11-21 N/A
Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server.
CVE-2018-10100 2 Debian, Wordpress 2 Debian Linux, Wordpress 2024-11-21 N/A
Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.