CVE List

Id CVE No. Status Description Phase Votes Comments Actions
49740  CVE-2011-1828  Candidate  usb-creator-helper in usb-creator before 0.2.28.3 does not enforce intended PolicyKit restrictions, which allows local users to perform arbitrary unmount operations via the UnmountFile method in a dbus-send command.  Assigned (20110427)  None (candidate not yet proposed)    View
61010  CVE-2013-1063  Candidate  usb-creator 0.2.47 before 0.2.47.1, 0.2.40 before 0.2.40ubuntu2, and 0.2.38 before 0.2.38.2 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.  Assigned (20130111)  None (candidate not yet proposed)    View
103731  CVE-2017-6911  Candidate  USB Pratirodh is prone to sensitive information disclosure. It stores sensitive information such as username and password in simple usb.xml. An attacker with physical access to the system can modify the file according his own requirements that may aid in further attack.  Assigned (20170315)  None (candidate not yet proposed)    View
103715  CVE-2017-6895  Candidate  USB Pratirodh allows remote attackers to conduct XML External Entity (XXE) attacks via XML data in usb.xml.  Assigned (20170314)  None (candidate not yet proposed)    View
68582  CVE-2014-1287  Candidate  USB Host in Apple iOS before 7.1 and Apple TV before 6.1 allows physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted USB messages.  Assigned (20140108)  None (candidate not yet proposed)    View

Page 807 of 20943, showing 5 records out of 104715 total, starting on record 4031, ending on 4035

Actions