|
287461
|
- |
|
wellintech
|
kinggraphic kingscada kingalarm\&event
|
WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 perform authentication on the KAEClientManager console rather than on the server, which allows remote attac…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2826
|
2024-11-21 10:52 |
2014-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287462
|
- |
|
sierrawireless
|
raven_x_ev-do_firmware airlink_mp_at\&t airlink_mp_at\&t_wifi airlink_mp_bell airlink_mp_bell_wifi airlink_mp_row airlink_mp_row_wifi airlink_mp_sprint airlink_mp_spri…
|
The Sierra Wireless AirLink Raven X EV-DO gateway 4221_4.0.11.003 and 4228_4.0.11.003 allows remote attackers to reprogram the firmware via a replay attack using UDP ports 17336 and 17388.
|
CWE-287
Improper Authentication
|
CVE-2013-2820
|
2024-11-21 10:52 |
2014-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287463
|
- |
|
sierrawireless
|
raven_x_ev-do_firmware airlink_mp_at\&t airlink_mp_at\&t_wifi airlink_mp_bell airlink_mp_bell_wifi airlink_mp_row airlink_mp_row_wifi airlink_mp_sprint airlink_mp_spri…
|
The Sierra Wireless AirLink Raven X EV-DO gateway 4221_4.0.11.003 and 4228_4.0.11.003 allows remote attackers to install Trojan horse firmware by leveraging cleartext credentials in a crafted (1) upd…
|
CWE-255
Credentials Management
|
CVE-2013-2819
|
2024-11-21 10:52 |
2014-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287464
|
- |
|
idleman
|
leed
|
Leed (Light Feed), possibly before 1.5 Stable, allows remote attackers to bypass authorization via vectors related to the (1) importForm, (2) importFeed, (3) addFavorite, or (4) removeFavorite action…
|
CWE-20
Improper Input Validation
|
CVE-2013-2629
|
2024-11-21 10:52 |
2013-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287465
|
- |
|
novatech
|
orion5_dnp_slave orionlx_dnp_slave orion5r_dnp_master orion5r_dnp_slave orionlx_dnp_master orion5_dnp_master
|
NovaTech Orion Substation Automation Platform OrionLX DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier and Orion5/Orion5r DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier allow physically pro…
|
CWE-20
Improper Input Validation
|
CVE-2013-2822
|
2024-11-21 10:52 |
2013-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287466
|
- |
|
novatech
|
orion5_dnp_slave orionlx_dnp_slave orion5r_dnp_master orion5r_dnp_slave orionlx_dnp_master orion5_dnp_master
|
NovaTech Orion Substation Automation Platform OrionLX DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier and Orion5/Orion5r DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier allow remote attacke…
|
CWE-20
Improper Input Validation
|
CVE-2013-2821
|
2024-11-21 10:52 |
2013-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287467
|
- |
|
idleman
|
leed
|
Multiple cross-site request forgery (CSRF) vulnerabilities in action.php in Leed (Light Feed), possibly before 1.5 Stable, allow remote attackers to hijack the authentication of administrators for un…
|
CWE-352
Origin Validation Error
|
CVE-2013-2628
|
2024-11-21 10:52 |
2013-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287468
|
- |
|
idleman
|
leed
|
SQL injection vulnerability in action.php in Leed (Light Feed), possibly before 1.5 Stable, allows remote attackers to execute arbitrary SQL commands via the id parameter in a removeFolder action.
|
CWE-89
SQL Injection
|
CVE-2013-2627
|
2024-11-21 10:52 |
2013-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287469
|
- |
|
cooperindustries
|
smp_4_gateway_\(data_concentrator\) smp_4\/dp_gateway_\(data_concentrator\) smp_16_gateway_\(data_concentrator\)
|
The DNP3 component in Cooper Power Systems SMP 4, 4/DP, and 16 gateways allows physically proximate attackers to cause a denial of service (reboot or link outage) via crafted input over a serial line.
|
CWE-20
Improper Input Validation
|
CVE-2013-2816
|
2024-11-21 10:52 |
2013-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287470
|
- |
|
cooperindustries
|
dnp3_master_opc_server
|
Cooper Power Systems Cybectec DNP3 Master OPC Server allows remote attackers to cause a denial of service (unhandled exception and process crash) via unspecified vectors.
|
CWE-20
Improper Input Validation
|
CVE-2013-2814
|
2024-11-21 10:52 |
2013-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|