Search: "sir"

157 CVEs found

CVE-2015-2081
9.8 CRITICAL

Datto ALTO and SIRIS devices allow Remote Code Execution via unauthenticated requests to PHP scripts.

Published: 2018-02-20
Products: 16
Vendors:
datto
CVE-2015-9254
9.8 CRITICAL

Datto ALTO and SIRIS devices have a default VNC password.

Published: 2018-02-20
Products: 16
Vendors:
datto
CVE-2015-9255
5.3 MEDIUM

Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information about data, software versions, configuration, and virtual machines via a request to a Web Virtual Directory.

Published: 2018-02-20
Products: 16
Vendors:
datto
CVE-2015-9256
5.3 MEDIUM

Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information via access to device/VM restore mount points, because they do not have ACLs by default.

Published: 2018-02-20
Products: 16
Vendors:
datto
CVE-2018-0015
9.8 CRITICAL

A malicious user with unrestricted access to the AppFormix application management platform may be able to access a Python debug console and execute system commands with root privilege. The AppFormix A...

Published: 2018-02-22
Products: 3
Vendors:
juniper

Junos OS may be impacted by the receipt of a malformed BGP UPDATE which can lead to a routing process daemon (rpd) crash and restart. Receipt of a repeated malformed BGP UPDATEs can result in an exten...

Published: 2018-04-11
Products: 177
Vendors:
juniper

An issue was discovered in certain Apple products. iOS before 11.4 is affected. The issue involves the "Siri" component. It allows physically proximate attackers to bypass the lock-screen protection m...

Published: 2018-06-08
Products: 1
Vendors:
apple
CVE-2018-4244
4.6 MEDIUM

An issue was discovered in certain Apple products. iOS before 11.4 is affected. The issue involves the "Siri Contacts" component. It allows physically proximate attackers to discover private contact i...

Published: 2018-06-08
Products: 1
Vendors:
apple
CVE-2018-4252
4.6 MEDIUM

An issue was discovered in certain Apple products. iOS before 11.4 is affected. The issue involves the "Siri" component. It allows physically proximate attackers to bypass the lock-screen protection m...

Published: 2018-06-08
Products: 1
Vendors:
apple

A vulnerability in the DHCPv6 input packet processor of Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to restart the server and cause a denial of service (DoS) conditio...

Published: 2019-04-18
Products: 2
Vendors:
cisco
CVE-2019-11081
9.8 CRITICAL

A default username and password in Dentsply Sirona Sidexis 4.3.1 and earlier allows an attacker to gain administrative access to the application server.

Published: 2019-04-24
Products: 1
Vendors:
dentsplysirona

The sirv plugin before 1.3.2 for WordPress has SQL injection via the id parameter.

Published: 2019-09-13
Products: 1
Vendors:
sirv

A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an una...

Published: 2020-05-04
Products: 277
Vendors:
juniper

An API issue existed in the handling of outgoing phone calls initiated with Siri. This issue was addressed with improved state handling. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1,...

Published: 2020-10-27
Products: 4
Vendors:
apple

An issue existed with Siri Suggestions access to encrypted data. The issue was fixed by limiting access to encrypted data. This issue is fixed in macOS Catalina 10.15.3, Security Update 2020-001 Mojav...

Published: 2020-10-27
Products: 1
Vendors:
apple
CVE-2020-1908
4.6 MEDIUM

Improper authorization of the Screen Lock feature in WhatsApp and WhatsApp Business for iOS prior to v2.20.100 could have permitted use of Siri to interact with the WhatsApp application even after the...

Published: 2020-11-03
Products: 2
Vendors:
whatsapp
CVE-2021-28938
4.3 MEDIUM

Siren Federate before 6.8.14-10.3.9, 6.9.x through 7.6.x before 7.6.2-20.2, 7.7.x through 7.9.x before 7.9.3-21.6, 7.10.x before 7.10.2-22.2, and 7.11.x before 7.11.2-23.0 can leak user information ac...

Published: 2021-04-13
Products: 4
Vendors:
siren

Siren Investigate before 11.1.1 contains a server side request forgery (SSRF) defect in the built-in image proxy route (which is enabled by default). An attacker with access to the Investigate install...

Published: 2021-07-19
Products: 1
Vendors:
siren

Description: A person with physical access may be able to access contacts. This issue is fixed in iOS 14.5 and iPadOS 14.5. Impact: An issue with Siri search access to information was addressed with i...

Published: 2021-09-08
Products: 2
Vendors:
apple
CVE-2021-36794
9.8 CRITICAL

In Siren Investigate before 11.1.4, when enabling the cluster feature of the Siren Alert application, TLS verifications are disabled globally in the Siren Investigate main process.

Published: 2021-11-02
Products: 1
Vendors:
siren