Lucene search

K

Ar Security Vulnerabilities

cve
cve

CVE-2023-33412

The web interface in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions before 3.17.02, allows remote authenticated users to execute arbitrary commands via a crafted request...

8.8CVSS

8.5AI Score

0.001EPSS

2023-12-07 06:15 PM
14
cve
cve

CVE-2023-33411

A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions up to 3.17.02, allows remote unauthenticated users to perform directory traversal, potentially disclosing...

7.5CVSS

7.5AI Score

0.001EPSS

2023-12-07 06:15 PM
9
cve
cve

CVE-2023-33413

The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions through 3.17.02, allows remote authenticated users to execute arbitrary...

8.8CVSS

8.6AI Score

0.001EPSS

2023-12-07 06:15 PM
12
cve
cve

CVE-2023-34853

Buffer Overflow vulnerability in Supermicro motherboard X12DPG-QR 1.4b allows local attackers to hijack control flow via manipulation of SmcSecurityEraseSetupVar...

7.8CVSS

7.5AI Score

0.0004EPSS

2023-08-22 07:16 PM
25
cve
cve

CVE-2023-35861

A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to inject execute arbitrary commands as root on the...

9.8CVSS

9.6AI Score

0.001EPSS

2023-07-31 01:15 PM
32
cve
cve

CVE-2018-20438

Technicolor TC7110.AR STD3.38.03 devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.2863.205.10.1.30.4.1.14.1.3.32 and iso.3.6.1.4.1.2863.205.10.1.30.4.2.4.1.2.32 SNMP...

9.8CVSS

9.4AI Score

0.006EPSS

2022-10-03 04:22 PM
23
cve
cve

CVE-2018-20393

Technicolor CGA0111 CGA0111E-ES-13-E23E-c8000r5712-170217-0829-TRU, CWA0101 CWA0101E-A23E-c7000r5712-170315-SKC, DPC3928SL D3928SL-PSIP-13-A010-c3420r55105-170214a, TC7110.AR STD3.38.03, TC7110.B STC8.62.02, TC7110.D STDB.79.02, TC7200.d1I TC7200.d1IE-N23E-c7000r5712-170406-HAT, and TC7200.TH2v2...

9.8CVSS

9.4AI Score

0.005EPSS

2022-10-03 04:22 PM
31
cve
cve

CVE-2012-6569

Stack-based buffer overflow in the HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, S7800, and S8500 switches allows remote attackers to execute arbitrary code via a long...

8.3AI Score

0.004EPSS

2022-10-03 04:15 PM
22
cve
cve

CVE-2012-6570

The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, S7800, and S8500 switches does not check whether HTTP data is longer than the value of the Content-Length field, which allows.....

8.1AI Score

0.003EPSS

2022-10-03 04:15 PM
24
cve
cve

CVE-2012-6571

The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, and S7800 switches uses predictable Session ID values, which makes it easier for remote attackers to hijack sessions via a...

6.8AI Score

0.003EPSS

2022-10-03 04:15 PM
23
cve
cve

CVE-2013-4631

Huawei AR 150, 200, 1200, 2200, and 3200 routers, when SNMPv3 is enabled, allow remote attackers to cause a denial of service (device crash) via malformed SNMPv3 requests that leverage unspecified overflow...

7.1AI Score

0.002EPSS

2022-10-03 04:14 PM
21
cve
cve

CVE-2021-25441

Improper input validation vulnerability in AR Emoji Editor prior to version 4.4.03.5 in Android Q(10.0) and above allows untrusted applications to access arbitrary files with an escalated...

7.8CVSS

7.4AI Score

0.0004EPSS

2021-07-08 02:15 PM
23
cve
cve

CVE-2021-25664

A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2017.02.4), Nucleus ReadyStart V4 (All versions < V4.1.0), Nucleus Source...

7.5CVSS

7.5AI Score

0.002EPSS

2021-04-22 09:15 PM
31
4
cve
cve

CVE-2021-25663

A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2017.02.4), Nucleus ReadyStart V4 (All versions < V4.1.0), Nucleus Source...

7.5CVSS

7.4AI Score

0.002EPSS

2021-04-22 09:15 PM
37
4
cve
cve

CVE-2018-8062

A cross-site scripting (XSS) vulnerability on Comtrend AR-5387un devices with A731-410JAZ-C04_R02.A2pD035g.d23i firmware allows remote attackers to inject arbitrary web script or HTML via the Service Description parameter while creating a WAN...

5.4CVSS

5.3AI Score

0.001EPSS

2020-10-23 05:15 AM
47
cve
cve

CVE-2020-8168

We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the description below:Attackers can abuse multiple end-points not protected against cross-site request....

8.8CVSS

8.8AI Score

0.001EPSS

2020-05-26 04:15 PM
62
cve
cve

CVE-2020-8171

We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the description below:There are certain end-points containing functionalities that are vulnerable to...

9.8CVSS

10AI Score

0.046EPSS

2020-05-26 04:15 PM
52
cve
cve

CVE-2020-8170

We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the description below:Multiple end-points with parameters vulnerable to reflected cross site scripting....

6.1CVSS

6.5AI Score

0.001EPSS

2020-05-26 04:15 PM
58
cve
cve

CVE-2019-13939

A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2017.02.3), Nucleus Source Code (All versions). By sending specially crafted...

7.1CVSS

6.7AI Score

0.001EPSS

2020-01-16 04:15 PM
54
1
cve
cve

CVE-2015-5072

The BIRT Engine servlet in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote authenticated users to "navigate" to arbitrary local files via the __imageid...

6.5CVSS

6.2AI Score

0.001EPSS

2020-01-15 06:15 PM
38
cve
cve

CVE-2015-5071

AR System Mid Tier in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote authenticated users to "navigate" to arbitrary files via the __report parameter of the BIRT viewer...

6.5CVSS

6.2AI Score

0.001EPSS

2020-01-15 06:15 PM
39
cve
cve

CVE-2019-15414

The Asus ZenFone AR Android device with a build fingerprint of asus/WW_ASUS_A002/ASUS_A002:7.0/NRD90M/14.1600.1805.51-20180626:user/release-keys contains a pre-installed app with a package name of com.asus.splendidcommandagent app (versionCode=1510200105, versionName=1.2.0.21_180605) that allows...

7.8CVSS

7.5AI Score

0.0004EPSS

2019-11-14 05:15 PM
19
cve
cve

CVE-2019-15402

The Asus ASUS_A002_2 Android device with a build fingerprint of asus/WW_ASUS_A002_2/ASUS_A002_2:7.0/NRD90M/14.1610.1802.18-20180321:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000020, versionName=7.0.0.4_170901) that allows...

7.8CVSS

7.5AI Score

0.0004EPSS

2019-11-14 05:15 PM
17
cve
cve

CVE-2019-15401

The Asus ASUS_A002 Android device with a build fingerprint of asus/WW_ASUS_A002/ASUS_A002:7.0/NRD90M/14.1600.1805.51-20180626:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000020, versionName=7.0.0.4_170901) that allows other...

7.8CVSS

7.5AI Score

0.0004EPSS

2019-11-14 05:15 PM
23
cve
cve

CVE-2009-5156

An issue was discovered on ASMAX AR-804gu 66.34.1 devices. There is Command Injection via the cgi-bin/script query...

9.8CVSS

9.7AI Score

0.024EPSS

2019-06-11 09:29 PM
77
cve
cve

CVE-2019-6451

On SOYAL AR-727H and AR-829Ev5 devices, all CGI programs allow unauthenticated POST...

7.5CVSS

7.6AI Score

0.003EPSS

2019-06-06 07:29 PM
150
cve
cve

CVE-2017-5712

Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access to the system to execute arbitrary code with AMT execution...

7.2CVSS

7.5AI Score

0.012EPSS

2017-11-21 02:29 PM
145
cve
cve

CVE-2017-5711

Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code with AMT execution...

7.8CVSS

7.4AI Score

0.0004EPSS

2017-11-21 02:29 PM
34
cve
cve

CVE-2015-8086

Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software before...

4.9CVSS

4.7AI Score

0.001EPSS

2016-10-03 09:59 PM
20
cve
cve

CVE-2015-8085

Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software before...

4.9CVSS

4.9AI Score

0.001EPSS

2016-10-03 09:59 PM
18
cve
cve

CVE-2016-6901

Format string vulnerability in Huawei AR100, AR120, AR150, AR200, AR500, AR550, AR1200, AR2200, AR2500, AR3200, and AR3600 routers with software before V200R007C00SPC900 and NetEngine 16EX routers with software before V200R007C00SPC900 allows remote authenticated users to cause a denial of service....

6.5CVSS

5.8AI Score

0.002EPSS

2016-09-26 04:59 PM
23
cve
cve

CVE-2015-8228

Directory traversal vulnerability in the SFTP server in Huawei AR 120, 150, 160, 200, 500, 1200, 2200, 3200, and 3600 routers with software before V200R006SPH003 allows remote authenticated users to access arbitrary directories via unspecified...

6.5AI Score

0.001EPSS

2015-11-24 08:59 PM
19
cve
cve

CVE-2013-4630

Stack-based buffer overflow on Huawei AR 150, 200, 1200, 2200, and 3200 routers, when SNMPv3 debugging is enabled, allows remote attackers to execute arbitrary code via malformed SNMPv3...

8.4AI Score

0.028EPSS

2013-06-20 03:55 PM
24
cve
cve

CVE-2012-4960

The Huawei NE5000E, MA5200G, NE40E, NE80E, ATN, NE40, NE80, NE20E-X6, NE20, ME60, CX600, CX200, CX300, ACU, WLAN AC 6605, S9300, S7700, S2300, S3300, S5300, S3300HI, S5300HI, S5306, S6300, S2700, S3700, S5700, S6700, AR G3, H3C AR(OEM IN), AR 19, AR 29, AR 49, Eudemon100E, Eudemon200, Eudemon300,.....

6.4AI Score

0.009EPSS

2013-06-20 03:55 PM
32
cve
cve

CVE-2012-2438

ar web content manager (AWCM) 2.2 does not restrict the number of comment records that can be submitted through HTTP requests, which allows remote attackers to cause a denial of service (disk consumption) via the coment parameter to (1) show_video.php or (2)...

6.8AI Score

0.008EPSS

2012-11-26 12:45 PM
18
cve
cve

CVE-2012-2437

cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary cookies via the name parameter in conjunction with the content...

6.9AI Score

0.057EPSS

2012-11-26 12:45 PM
21
cve
cve

CVE-2010-4810

Multiple PHP remote file inclusion vulnerabilities in AR Web Content Manager (AWCM) 2.1 final allow remote attackers to execute arbitrary PHP code via a URL in the theme_file parameter to (1) includes/window_top.php and (2) header.php, and the (3) lang_file parameter to...

7.8AI Score

0.012EPSS

2011-07-08 10:55 PM
33
cve
cve

CVE-2011-1668

Cross-site scripting (XSS) vulnerability in search.php in AR Web Content Manager (AWCM) 2.1, 2.2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the search...

6AI Score

0.005EPSS

2011-04-10 02:51 AM
24
cve
cve

CVE-2011-0903

Multiple directory traversal vulnerabilities in AR Web Content Manager (AWCM) 2.2 allow remote attackers to read arbitrary files and possibly have other unspecified impact via a .. (dot dot) in the (1) awcm_theme or (2) awcm_lang cookie to (a) index.php or (b)...

7.3AI Score

0.009EPSS

2011-02-07 09:00 PM
19
cve
cve

CVE-2010-1066

AR Web Content Manager (AWCM) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for...

6.5AI Score

0.005EPSS

2010-03-23 06:30 PM
23
cve
cve

CVE-2009-3218

SQL injection vulnerability in control/login.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username...

8.4AI Score

0.001EPSS

2009-09-16 07:30 PM
24
cve
cve

CVE-2009-3219

Directory traversal vulnerability in a.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the a...

7.1AI Score

0.005EPSS

2009-09-16 07:30 PM
22
cve
cve

CVE-2006-6590

PHP remote file inclusion vulnerability in usercp_menu.php in AR Memberscript allows remote attackers to execute arbitrary PHP code via a URL in the script_folder...

7.9AI Score

0.047EPSS

2006-12-15 07:28 PM
33
cve
cve

CVE-2006-2809

Multiple cross-site scripting (XSS) vulnerabilities in index.php in ar-blog 5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) count parameter, and possibly the (2) next, (3) Year_the_news, and (4) mo parameters. NOTE: the year and month vectors are already covered by...

5.8AI Score

0.005EPSS

2006-06-05 05:02 PM
20
cve
cve

CVE-2006-1893

Cross-site scripting (XSS) vulnerability in print.php in ar-blog 5.2 allows remote attackers to inject arbitrary web script or HTML via the id...

5.7AI Score

0.007EPSS

2006-04-20 10:02 AM
17
cve
cve

CVE-2006-0333

Cross-site scripting (XSS) vulnerability in ar-blog 5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) month or (2) year parameter to...

5.6AI Score

0.003EPSS

2006-01-21 12:03 AM
21
cve
cve

CVE-2005-3495

Ar-blog 5.2 and earlier allows remote attackers to bypass authentication by modifying...

7.4AI Score

0.008EPSS

2005-11-04 12:02 AM
19
cve
cve

CVE-2005-3494

Cross-site scripting (XSS) vulnerability in Ar-blog 5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a blog...

5.9AI Score

0.004EPSS

2005-11-04 12:02 AM
23