Lucene search

K

R Security Vulnerabilities

cve
cve

CVE-2017-15361

The Infineon RSA library 1.02.013 in Infineon Trusted Platform Module (TPM) firmware, such as versions before 0000000000000422 - 4.34, before 000000000000062b - 6.43, and before 0000000000008521 - 133.33, mishandles RSA key generation, which makes it easier for attackers to defeat various...

5.9CVSS

5.7AI Score

0.004EPSS

2017-10-16 05:29 PM
151
2
cve
cve

CVE-2017-8012

In EMC ViPR SRM, Storage M&R, VNX M&R, and M&R (Watch4Net) for SAS Solution Packs, the Java Management Extensions (JMX) protocol used to communicate between components in the Alerting and/or Compliance components can be leveraged to create a denial of service (DoS) condition. Attackers with...

7.4CVSS

7.3AI Score

0.004EPSS

2017-09-22 01:29 AM
28
cve
cve

CVE-2017-8007

In EMC ViPR SRM, Storage M&R, VNX M&R, and M&R (Watch4Net) for SAS Solution Packs, the Webservice Gateway is affected by a directory traversal vulnerability. Attackers with knowledge of Webservice Gateway credentials could potentially exploit this vulnerability to access unauthorized information,.....

8.8CVSS

8.6AI Score

0.002EPSS

2017-09-22 01:29 AM
22
cve
cve

CVE-2017-8011

EMC ViPR SRM, EMC Storage M&R, EMC VNX M&R, EMC M&R for SAS Solution Packs (EMC ViPR SRM prior to 4.1, EMC Storage M&R prior to 4.1, EMC VNX M&R all versions, EMC M&R (Watch4Net) for SAS Solution Packs all versions) contain undocumented accounts with default passwords for Webservice Gateway and...

9.8CVSS

9.4AI Score

0.007EPSS

2017-07-17 02:29 PM
23
cve
cve

CVE-2016-8714

An exploitable buffer overflow vulnerability exists in the LoadEncoding functionality of the R programming language version 3.3.0. A specially crafted R script can cause a buffer overflow resulting in a memory corruption. An attacker can send a malicious R script to trigger this...

8.8CVSS

8AI Score

0.002EPSS

2017-03-10 10:59 AM
55
cve
cve

CVE-2016-4573

Fortinet FortiSwitch FSW-108D-POE, FSW-124D, FSW-124D-POE, FSW-224D-POE, FSW-224D-FPOE, FSW-248D-POE, FSW-248D-FPOE, FSW-424D, FSW-424D-POE, FSW-424D-FPOE, FSW-448D, FSW-448D-POE, FSW-448D-FPOE, FSW-524D, FSW-524D-FPOE, FSW-548D, FSW-548D-FPOE, FSW-1024D, FSW-1048D, FSW-3032D, and FSW-R-112D-POE...

9.8CVSS

9.8AI Score

0.005EPSS

2016-09-09 02:05 PM
16
cve
cve

CVE-2016-4821

I-O DATA DEVICE ETX-R devices allow remote attackers to cause a denial of service (web-server crash) via unspecified...

5.3CVSS

5.3AI Score

0.004EPSS

2016-06-19 01:59 AM
17
cve
cve

CVE-2016-4820

Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE ETX-R devices allows remote attackers to hijack the authentication of arbitrary...

8.8CVSS

9AI Score

0.002EPSS

2016-06-19 01:59 AM
18
cve
cve

CVE-2015-7288

CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 allow remote attackers to modify the configuration via a command in an SMS message, as demonstrated by a "4 2"...

7.1AI Score

0.004EPSS

2015-11-25 04:59 AM
21
cve
cve

CVE-2015-7287

CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 use the same 001984 default PIN across different customers' installations, which allows remote attackers to execute commands by leveraging knowledge of this PIN and including it in an SMS...

7.6AI Score

0.021EPSS

2015-11-25 04:59 AM
24
cve
cve

CVE-2015-7286

CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 rely on a polyalphabetic substitution cipher with hardcoded keys, which makes it easier for remote attackers to defeat a cryptographic protection mechanism by capturing IP or V.22bis PSTN protocol...

7.1AI Score

0.006EPSS

2015-11-25 04:59 AM
18
cve
cve

CVE-2015-7285

CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 do not require authentication from Alarm Receiving Center (ARC) servers, which allows man-in-the-middle attackers to bypass intended access restrictions via a spoofed HSxx...

7.1AI Score

0.001EPSS

2015-11-25 04:59 AM
21
cve
cve

CVE-2001-1594

GE Healthcare eNTEGRA P&R has a password of (1) entegra for the entegra user, (2) passme for the super user of the Polestar/Polestar-i Starlink 4 upgrade, (3) 0 for the entegra user of the Codonics printer FTP service, (4) eNTEGRA for the eNTEGRA P&R user account, (5) insite for the WinVNC Login,.....

9.5AI Score

0.003EPSS

2015-08-04 02:59 PM
21
cve
cve

CVE-2012-1250

Logitec LAN-W300N/R routers with firmware before 2.27 do not properly restrict login access, which allows remote attackers to obtain administrative privileges and modify settings via vectors related to PPPoE...

6.9AI Score

0.01EPSS

2012-06-04 05:55 PM
27
cve
cve

CVE-2010-3931

Cross-site scripting (XSS) vulnerability in multiple Rocomotion products, including P board 1.18 and other versions, P forum 1.30 and earlier, P up board 1.38 and other versions, P diary R 1.13 and earlier, P link 1.11 and earlier, P link compact 1.04 and earlier, pplog 3.31 and earlier, pplog2...

5.9AI Score

0.002EPSS

2011-01-20 07:00 PM
25
cve
cve

CVE-2008-3931

javareconf in R 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary...

6AI Score

0.0004EPSS

2008-09-04 06:41 PM
22
cve
cve

CVE-2007-4750

Unspecified vulnerability in RemoteDocs R-Viewer before 1.6.3768 allows user-assisted remote attackers to execute arbitrary code via a crafted RDZ archive in which the first file has an executable...

7.4AI Score

0.061EPSS

2007-09-18 09:17 PM
30
cve
cve

CVE-2007-4751

RemoteDocs R-Viewer before 1.6.3768 stores encrypted RDZ file data in unencrypted temporary files, which allows local users to obtain sensitive information by reading the temporary...

5.7AI Score

0.0004EPSS

2007-09-18 09:17 PM
34
cve
cve

CVE-2005-4815

SAP 6.4 before 6.40 patch 4, 6.2 before 6.20 patch 1364, 4.6 before 4.6D patch 1767, 45 before 45B patch 913, 40 before 40B patch 1008, and 31 before 31I patch 735 do not properly restrict process execution by lnaxdm/sapsys, which allows remote attackers to execute arbitrary code via a certain UDP....

8AI Score

0.062EPSS

2006-11-21 11:00 PM
19
cve
cve

CVE-2002-1752

csChatRBox.cgi in CGIScript.net csChat-R-Box allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval...

7.5AI Score

0.003EPSS

2005-06-21 04:00 AM
38
cve
cve

CVE-2002-1577

SAP R/3 2.0B to 4.6D installs several clients with default users and passwords, which allows remote attackers to gain privileges via the (1) SAP*, (2) SAPCPIC, (3) DDIC, (4) EARLYWATCH, or (5) TMSADM...

7.4AI Score

0.009EPSS

2004-04-15 04:00 AM
26
cve
cve

CVE-2003-1035

The default installation of SAP R/3 46C/D allows remote attackers to bypass account locking by using the RFC API instead of the SAPGUI to conduct a brute force password guessing attack, which does not lock out the account like the SAPGUI...

7.3AI Score

0.011EPSS

2004-04-15 04:00 AM
26
cve
cve

CVE-2002-1578

The default installation of SAP R/3, when using Oracle and SQL*net V2 3.x, 4.x, and 6.10, allows remote attackers to obtain arbitrary, sensitive SAP data by directly connecting to the Oracle database and executing queries against the database, which is not...

6.6AI Score

0.016EPSS

2004-04-15 04:00 AM
22
cve
cve

CVE-2001-0366

saposcol in SAP R/3 Web Application Server Demo before 1.5 trusts the PATH environmental variable to find and execute the expand program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse expand...

6.8AI Score

0.0004EPSS

2002-03-09 05:00 AM
25
cve
cve

CVE-2000-0379

The Netopia R9100 router does not prevent authenticated users from modifying SNMP tables, even if the administrator has configured it to do...

6.8AI Score

0.001EPSS

2000-07-12 04:00 AM
24
Total number of security vulnerabilities1675