|
285541
|
- |
|
cisco
|
prime_central_for_hosted_collaboration_solution_assurance
|
The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance before 9.1.1 does not properly determine the existence of an authenticated session, which allows remote atta…
|
CWE-287
Improper Authentication
|
CVE-2013-3473
|
2024-11-21 10:53 |
2013-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285542
|
- |
|
dahuasecurity
|
dvr2104h dvr0404hd-a dvr1604hd-l dvr2104hc dvr5216a dvr5104he dvr3204lf-al dvr5204a dvr3204hf-s dvr0404hd-s dvr0804 dvr5104h dvr5804 dvr2116h dvr2404lf-al
|
Dahua DVR appliances use a password-hash algorithm with a short hash length, which makes it easier for context-dependent attackers to discover cleartext passwords via a brute-force attack.
|
CWE-255
Credentials Management
|
CVE-2013-3615
|
2024-11-21 10:53 |
2013-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285543
|
- |
|
dahuasecurity
|
dvr2104h dvr0404hd-a dvr1604hd-l dvr2104hc dvr5216a dvr5104he dvr3204lf-al dvr5204a dvr3204hf-s dvr0404hd-s dvr0804 dvr5104h dvr5804 dvr2116h dvr2404lf-al
|
Dahua DVR appliances do not properly restrict UPnP requests, which makes it easier for remote attackers to obtain access via vectors involving a replay attack against the TELNET port.
|
CWE-287
Improper Authentication
|
CVE-2013-3613
|
2024-11-21 10:53 |
2013-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285544
|
- |
|
dahuasecurity
|
dvr2104h dvr0404hd-a dvr1604hd-l dvr2104hc dvr5216a dvr5104he dvr3204lf-al dvr5204a dvr3204hf-s dvr0404hd-s dvr0804 dvr5104h dvr5804 dvr2116h dvr2404lf-al
|
Dahua DVR appliances have a small value for the maximum password length, which makes it easier for remote attackers to obtain access via a brute-force attack.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-3614
|
2024-11-21 10:53 |
2013-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285545
|
- |
|
dahuasecurity
|
dvr2104h dvr0404hd-a dvr1604hd-l dvr2104hc dvr5216a dvr5104he dvr3204lf-al dvr5204a dvr3204hf-s dvr0404hd-s dvr0804 dvr5104h dvr5804 dvr2116h dvr2404lf-al
|
Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which makes it easier for remote attackers to obtain administrative access via autho…
|
CWE-255
Credentials Management
|
CVE-2013-3612
|
2024-11-21 10:53 |
2013-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285546
|
- |
|
cisco
|
digital_media_manager
|
Open redirect vulnerability in the login page in Cisco Digital Media Manager (DMM) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vector…
|
CWE-20
Improper Input Validation
|
CVE-2013-3446
|
2024-11-21 10:53 |
2013-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285547
|
- |
|
adobe
|
flash_player air air_sdk
|
Adobe Flash Player before 11.7.700.242 and 11.8.x before 11.8.800.168 on Windows and Mac OS X, before 11.2.202.310 on Linux, before 11.1.111.73 on Android 2.x and 3.x, and before 11.1.115.81 on Andro…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-3363
|
2024-11-21 10:53 |
2013-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285548
|
- |
|
adobe
|
flash_player air air_sdk
|
Adobe Flash Player before 11.7.700.242 and 11.8.x before 11.8.800.168 on Windows and Mac OS X, before 11.2.202.310 on Linux, before 11.1.111.73 on Android 2.x and 3.x, and before 11.1.115.81 on Andro…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-3362
|
2024-11-21 10:53 |
2013-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285549
|
- |
|
adobe
|
flash_player air air_sdk
|
Adobe Flash Player before 11.7.700.242 and 11.8.x before 11.8.800.168 on Windows and Mac OS X, before 11.2.202.310 on Linux, before 11.1.111.73 on Android 2.x and 3.x, and before 11.1.115.81 on Andro…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-3361
|
2024-11-21 10:53 |
2013-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285550
|
- |
|
adobe
|
shockwave_player
|
Adobe Shockwave Player before 12.0.4.144 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-3360
|
2024-11-21 10:53 |
2013-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|