|
267521
|
8.8 |
HIGH
Adjacent
|
lemurmonitors
|
bluedriver
|
The Bluetooth functionality in Lemur Vehicle Monitors BlueDriver before 2016-04-07 supports unrestricted pairing without a PIN, which allows remote attackers to send arbitrary CAN commands by leverag…
|
CWE-284
Improper Access Control
|
CVE-2016-2354
|
2024-11-21 11:48 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267522
|
7.5 |
HIGH
Network
|
ecava
|
integraxor
|
The HMI web server in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive cleartext information by sniffing the network.
|
CWE-310
Cryptographic Issues
|
CVE-2016-2306
|
2024-11-21 11:48 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267523
|
6.1 |
MEDIUM
Network
|
ecava
|
integraxor
|
Cross-site scripting (XSS) vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
|
CWE-79
Cross-site Scripting
|
CVE-2016-2305
|
2024-11-21 11:48 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267524
|
4.3 |
MEDIUM
Network
|
ecava
|
integraxor
|
Ecava IntegraXor before 5.0 build 4522 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive inf…
|
CWE-200
Information Exposure
|
CVE-2016-2304
|
2024-11-21 11:48 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267525
|
5.3 |
MEDIUM
Network
|
ecava
|
integraxor
|
CRLF injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
|
NVD-CWE-Other
|
CVE-2016-2303
|
2024-11-21 11:48 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267526
|
5.3 |
MEDIUM
Network
|
ecava
|
integraxor
|
Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive information by reading detailed error messages.
|
CWE-200
Information Exposure
|
CVE-2016-2302
|
2024-11-21 11:48 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267527
|
6.3 |
MEDIUM
Network
|
ecava
|
integraxor
|
SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2016-2301
|
2024-11-21 11:48 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267528
|
6.5 |
MEDIUM
Network
|
ecava
|
integraxor
|
Ecava IntegraXor before 5.0 build 4522 allows remote attackers to bypass authentication and access unspecified web pages via unknown vectors.
|
CWE-287
Improper Authentication
|
CVE-2016-2300
|
2024-11-21 11:48 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267529
|
7.3 |
HIGH
Network
|
ecava
|
integraxor
|
SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2016-2299
|
2024-11-21 11:48 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267530
|
7.5 |
HIGH
Network
|
accuenergy
|
acuvim_ii_net_firmware acuvim_iir_net_firmware
|
The AXM-NET module in Accuenergy Acuvim II NET Firmware 3.08 and Acuvim IIR NET Firmware 3.08 allows remote attackers to discover a cleartext mail-server password via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2016-2294
|
2024-11-21 11:48 |
2016-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|