| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Vulnerability in YingZhi Python Programming Language v1.9 allows arbitrary anonymous uploads to the phone's storage |
| Transcend WiFiSD 1.8 has persistent XSS |
| PQI AirCard has persistent XSS |
| Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml binding |
| Ammyy Admin 3.2 and earlier stores the client ID at a fixed memory location, which might make it easier for user-assisted remote attackers to bypass authentication by running a local program that extracts a field from the AA_v3.2.exe file. |
| HMailServer 5.3.x and prior: Memory Corruption which could cause DOS |
| IBM Endpoint Manager for Remote Control 9.0.0 and 9.0.1 and Tivoli Remote Control 5.1.2 store multiple hashes of partial passwords, which makes it easier for remote attackers to decrypt passwords by leveraging access to the hashes. IBM X-Force ID: 88309. |
| IBM Worklight Consumer and Enterprise Editions 5.0.x before 5.0.6 Fix Pack 2 and 6.0.x before 6.0.0 Fix Pack 2, and Mobile Foundation Consumer and Enterprise Editions 5.0.x before 5.0.6 Fix Pack 2 and 6.0.0 Fix Pack 2 make it easier for attackers to defeat cryptographic protection mechanisms by leveraging improper initialization of the pseudo random number generator (PRNG) in Android and use of the Java Cryptography Architecture (JCA) by a Worklight program. IBM X-Force ID: 87128. |
| Cross-site Scripting (XSS) in EasyXDM before 2.4.18 allows remote attackers to inject arbitrary web script or html via the easyxdm.swf file. |
| The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks. |
| Cisco Linksys Routers EA2700, EA3500, E4200, EA4500: A bug can cause an unsafe TCP port to open which leads to unauthenticated access |
| Evernote prior to 5.5.1 has insecure password change |
| LastPass prior to 2.5.1 allows secure wipe bypass. |
| LastPass prior to 2.5.1 has an insecure PIN implementation. |
| Evernote before 5.5.1 has insecure PIN storage |
| A Code Execution vulnerability exists in select.py when using python-mode 2012-12-19. |
| Collabtive 1.0 has incorrect access control |
| Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream |
| AVTECH AVN801 DVR has a security bypass via the administration login captcha |
| Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials |