Search: "sir"

157 CVEs found

PHP remote file inclusion vulnerability in lire.php in Sire 2.0 nws allows remote attackers to execute arbitrary PHP code via a URL in the rub parameter.

Published: 2006-04-11
Products: 1
Vendors:
hubert_plisson
CVE-2006-1704
5.0 MEDIUM

Sire 2.0 nws allows remote attackers to upload arbitrary image files without authentication via a direct request to upload.php.

Published: 2006-04-11
Products: 1
Vendors:
hubert_plisson

Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execute arbitrary PHP code via a filepath parameter that contains a filename with a ....

Published: 2006-09-07
Products: 1
Vendors:
tiki
CVE-2007-4480
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in index.php in the Sirius 1.0 theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).

Published: 2007-08-22
Products: 1
Vendors:
wordpress
CVE-2009-0290
6.8 MEDIUM

Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the g4_path parameter. NOTE: in some...

Published: 2009-01-27
Products: 1
Vendors:
sir
CVE-2009-4575
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in the Q-Personel (com_qpersonel) component 1.0.2 RC2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the personel_sira paramete...

Published: 2010-01-06
Products: 2
Vendors:
qproje joomla

Siri in Apple iOS before 5.1 does not properly restrict the ability of Mail.app to handle voice commands, which allows physically proximate attackers to bypass the locked state via a command that forw...

Published: 2012-03-08
Products: 1
Vendors:
apple

Siri in Apple iOS before 7.1.2 allows physically proximate attackers to bypass an intended lock-screen passcode requirement, and read a contact list, via a Siri request that refers to a contact ambigu...

Published: 2014-07-01
Products: 9
Vendors:
apple

Siri in Apple iOS before 9 allows physically proximate attackers to bypass an intended client-side protection mechanism and obtain sensitive content-notification information by listening to a device i...

Published: 2015-09-18
Products: 1
Vendors:
apple

Siri in Apple iOS before 9.2 allows physically proximate attackers to bypass an intended client-side protection mechanism and obtain sensitive content-notification information by listening to a device...

Published: 2015-12-11
Products: 1
Vendors:
apple

Siri in Apple iOS before 9.3.2 does not block data detectors within results in the lock-screen state, which allows physically proximate attackers to obtain sensitive contact and photo information via ...

Published: 2016-05-20
Products: 1
Vendors:
apple

The Siri Contacts component in Apple iOS before 9.3.3 allows physically proximate attackers to read arbitrary Contact card information via unspecified vectors.

Published: 2016-07-22
Products: 1
Vendors:
apple
CVE-2016-6530
9.8 CRITICAL

Dentsply Sirona (formerly Schick) CDR Dicom 5 and earlier has default passwords for the sa and cdr accounts, which allows remote attackers to obtain administrative access by leveraging knowledge of th...

Published: 2016-09-21
Products: 1
Vendors:
dentsply_sirona
CVE-2016-7597
4.6 MEDIUM

An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "SpringBoard" component, which allows physically proximate attackers to maintain the unlocked sta...

Published: 2017-02-20
Products: 1
Vendors:
apple

By flooding a Juniper Networks router running Junos OS with specially crafted IPv6 traffic, all available resources can be consumed, leading to the inability to store next hop information for legitima...

Published: 2017-10-13
Products: 71
Vendors:
juniper

Insufficient cross site scripting protection in J-Web component in Juniper Networks Junos OS may potentially allow a remote unauthenticated user to inject web script or HTML and steal sensitive data a...

Published: 2017-10-13
Products: 86
Vendors:
juniper

An incorrect permissions vulnerability in Juniper Networks Junos OS on vMX may allow local unprivileged users on a host system read access to vMX or vPFE images and obtain sensitive information contai...

Published: 2017-10-13
Products: 16
Vendors:
juniper

Receipt of a specifically malformed IPv6 packet processed by the router may trigger a line card reset: processor exception 0x68616c74 (halt) in task: scheduler. The line card will reboot and recover w...

Published: 2017-10-13
Products: 4
Vendors:
juniper

An issue was discovered in certain Apple products. iOS before 11.1 is affected. The issue involves the "Siri" component. It allows physically proximate attackers to obtain sensitive information via a ...

Published: 2017-11-13
Products: 1
Vendors:
apple

In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, currently, the value of SIR_MAC_AUTH_CHALLENGE_LENGTH is set to 128 which may result in ...

Published: 2017-11-16
Products: 1
Vendors:
google