Search: "dell"

1533 CVEs found

CVE-2004-0331
5.0 MEDIUM

Heap-based buffer overflow in Dell OpenManage Web Server 3.4.0 allows remote attackers to cause a denial of service (crash) via a HTTP POST with a long application variable.

Published: 2004-11-23
Products: 4
Vendors:
dell
CVE-2004-2359
10.0 HIGH

Dell TrueMobile 1300 WLAN Mini-PCI Card Util TrayApplet 3.10.39.0 does not properly drop SYSTEM privileges when started from the systray applet, which allows local users to gain privileges by accessin...

Published: 2004-12-31
Products: 1
Vendors:
dell
CVE-2005-3661
5.0 MEDIUM

Dell TrueMobile 2300 Wireless Broadband Router running firmware 3.0.0.8 and 5.1.1.6, and possibly other versions, allows remote attackers to reset authentication credentials, then change configuration...

Published: 2005-12-08
Products: 2
Vendors:
dell

The Dell Openmanage CD launches X11 and SSH daemons that do not require authentication, which allows remote attackers to gain privileges.

Published: 2006-07-10
Products: 1
Vendors:
dell

Fuji Xerox Printing Systems (FXPS) print engine, as used in products including (1) Dell 3000cn through 5110cn and (2) Fuji Xerox DocuPrint firmware before 20060628 and Network Option Card firmware bef...

Published: 2006-08-25
Products: 19
Vendors:
dell fuji_xerox
CVE-2006-2113
6.4 MEDIUM

The embedded HTTP server in Fuji Xerox Printing Systems (FXPS) print engine, as used in products including (1) Dell 3000cn through 5110cn and (2) Fuji Xerox DocuPrint firmware before 20060628 and Netw...

Published: 2006-08-25
Products: 19
Vendors:
dell fuji_xerox

The SJPhone SIP soft phone 1.60.303c, when installed on the Dell Axim X3 running Windows Mobile 2003, allows remote attackers to cause a denial of service (device hang and traffic amplification) via a...

Published: 2007-06-22
Products: 3
Vendors:
dell sj_labs microsoft
CVE-2007-4360
4.3 MEDIUM

Unspecified vulnerability in Dell Remote Access Card 4 (DRAC4) with firmware 1.50 Build 02.16 allows remote attackers to cause a denial of service (SSH daemon crash) via certain network traffic, as de...

Published: 2007-08-15
Products: 1
Vendors:
dell
CVE-2008-3253
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in the XenAPI HTTP interfaces in Citrix XenServer Express, Standard, and Enterprise Edition 4.1.0; Citrix XenServer Dell Edition (Express and Enterprise) 4.1.0...

Published: 2008-07-22
Products: 7
Vendors:
citrix

The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubuntu20.10.04.2 on Ubuntu 10.04 LTS, as shipped on Dell Latitude 2110 netbooks, does not require authentication for package...

Published: 2010-08-10
Products: 3
Vendors:
dell ubuntu
CVE-2011-0329
5.0 MEDIUM

Directory traversal vulnerability in the GetData method in the Dell DellSystemLite.Scanner ActiveX control in DellSystemLite.ocx 1.0.0.0 allows remote attackers to read arbitrary files via directory t...

Published: 2011-02-21
Products: 1
Vendors:
dell
CVE-2011-0330
5.0 MEDIUM

The Dell DellSystemLite.Scanner ActiveX control in DellSystemLite.ocx 1.0.0.0 does not properly restrict the values of the WMIAttributesOfInterest property, which allows remote attackers to execute ar...

Published: 2011-02-21
Products: 1
Vendors:
dell
CVE-2011-1672
5.0 MEDIUM

The Dell KACE K2000 Systems Deployment Appliance 3.3.36822 and earlier contains a peinst CIFS share, which allows remote attackers to obtain sensitive information by reading the (1) unattend.xml or (2...

Published: 2011-04-10
Products: 1
Vendors:
dell
CVE-2011-4046
5.0 MEDIUM

The Dell KACE K2000 System Deployment Appliance stores the recovery account password in cleartext within a PHP script, which allows context-dependent attackers to obtain sensitive information by exami...

Published: 2011-11-12
Products: 1
Vendors:
dell

The Dell KACE K2000 System Deployment Appliance allows remote attackers to execute arbitrary commands by leveraging database write access.

Published: 2011-11-12
Products: 1
Vendors:
dell
CVE-2011-4048
4.3 MEDIUM

The Dell KACE K2000 System Deployment Appliance has a default username and password for the read-only reporting account, which makes it easier for remote attackers to obtain sensitive information from...

Published: 2011-11-12
Products: 1
Vendors:
dell

Multiple cross-site scripting (XSS) vulnerabilities in the administrative web interface on the Dell KACE K2000 System Deployment Appliance allow remote attackers to inject arbitrary web script or HTML...

Published: 2011-11-12
Products: 1
Vendors:
dell
CVE-2012-1841
5.0 MEDIUM

Absolute path traversal vulnerability in logShow.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware ...

Published: 2012-03-22
Products: 22
Vendors:
dell quantum

Cross-site scripting (XSS) vulnerability in checkQKMProg.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with f...

Published: 2012-03-22
Products: 22
Vendors:
dell quantum
CVE-2012-1843
6.0 MEDIUM

Cross-site request forgery (CSRF) vulnerability in saveRestore.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library ...

Published: 2012-03-22
Products: 22
Vendors:
dell quantum