|
246371
|
9.8 |
CRITICAL
Network
|
grandstream
|
gxp1610_firmware gxp1615_firmware gxp1620_firmware gxp1625_firmware gxp1628_firmware gxp1630_firmware
|
A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete configuration parameters and gain admin access to the device.
|
NVD-CWE-noinfo
|
CVE-2018-17564
|
2024-11-21 12:54 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246372
|
5.3 |
MEDIUM
Network
|
grandstream
|
gxp1610_firmware gxp1615_firmware gxp1620_firmware gxp1625_firmware gxp1628_firmware gxp1630_firmware
|
A Malformed Input String to /cgi-bin/api-get_line_status on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to dump the device's configuration in cleartext.
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2018-17563
|
2024-11-21 12:54 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246373
|
3.3 |
LOW
Local
|
thereceptionist
|
the_receptionist_for_ipad
|
The Receptionist for iPad could allow a local attacker to obtain sensitive information, caused by an error in the contact.json file. An attacker could exploit this vulnerability to obtain the contact…
|
CWE-200
Information Exposure
|
CVE-2018-17502
|
2024-11-21 12:54 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246374
|
7.8 |
HIGH
Local
|
envoy
|
passport
|
Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of hardcoded OAuth Creds in plaintext. An attacker could e…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-17500
|
2024-11-21 12:54 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246375
|
5.5 |
MEDIUM
Local
|
envoy
|
passport
|
Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of unencrypted data in logs. An attacker could exploit thi…
|
CWE-532 CWE-312
Inclusion of Sensitive Information in Log Files Cleartext Storage of Sensitive Information
|
CVE-2018-17499
|
2024-11-21 12:54 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246376
|
7.8 |
HIGH
Local
|
thresholdsecurity
|
evisitorpass
|
eVisitorPass contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application.
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2018-17497
|
2024-11-21 12:54 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246377
|
7.8 |
HIGH
Local
|
thresholdsecurity
|
evisitorpass
|
eVisitorPass could allow a local attacker to gain elevated privileges on the system, caused by an error while in kiosk mode. By visiting the kiosk and typing ctrl+shift+esc, an attacker could exploit…
|
NVD-CWE-noinfo
|
CVE-2018-17496
|
2024-11-21 12:54 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246378
|
7.8 |
HIGH
Local
|
thresholdsecurity
|
evisitorpass
|
eVisitorPass could allow a local attacker to gain elevated privileges on the system, caused by an error with the Virtual Keyboard Help Dialog. By visiting the kiosk and removing the program from full…
|
NVD-CWE-noinfo
|
CVE-2018-17495
|
2024-11-21 12:54 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246379
|
7.8 |
HIGH
Local
|
thresholdsecurity
|
evisitorpass
|
eVisitorPass could allow a local attacker to gain elevated privileges on the system, caused by an error with the Virtual Keyboard Start Menu. By visiting the kiosk and pressing windows key twice, an …
|
NVD-CWE-noinfo
|
CVE-2018-17494
|
2024-11-21 12:54 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246380
|
7.8 |
HIGH
Local
|
thresholdsecurity
|
evisitorpass
|
eVisitorPass could allow a local attacker to gain elevated privileges on the system, caused by an error with the Fullscreen button. By visiting the kiosk and clicking the full screen button in the bo…
|
NVD-CWE-noinfo
|
CVE-2018-17493
|
2024-11-21 12:54 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|