{"resultsPerPage":10,"startIndex":0,"totalResults":75,"format":"NVD_CVE","version":"2.0","timestamp":"2026-07-21T02:10:59.444","vulnerabilities":[{"cve":{"id":"CVE-1999-1356","sourceIdentifier":"cve@mitre.org","published":"1999-09-02T04:00:00.000","lastModified":"2026-06-16T21:50:15.973","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Compaq Integration Maintenance Utility as used in Compaq Insight Manager agent before SmartStart 4.50 modifies the legal notice caption (LegalNoticeCaption) and text (LegalNoticeText) in Windows NT, which could produce a legal notice that is in violation of the security policy."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:compaq:smartstart:*:*:*:*:*:*:*:*","versionEndIncluding":"4.50","matchCriteriaId":"ED239855-5A0A-4C76-806A-DEDEC9819A74"}]}]}],"references":[{"url":"http://marc.info/?l=bugtraq&m=93646669500991&w=2","source":"cve@mitre.org"},{"url":"http://marc.info/?l=ntbugtraq&m=93637792706047&w=2","source":"cve@mitre.org"},{"url":"http://marc.info/?l=ntbugtraq&m=93759822830815&w=2","source":"cve@mitre.org"},{"url":"http://www.iss.net/security_center/static/7763.php","source":"cve@mitre.org"},{"url":"http://marc.info/?l=bugtraq&m=93646669500991&w=2","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://marc.info/?l=ntbugtraq&m=93637792706047&w=2","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://marc.info/?l=ntbugtraq&m=93759822830815&w=2","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.iss.net/security_center/static/7763.php","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-1999-0590","sourceIdentifier":"cve@mitre.org","published":"2000-06-01T04:00:00.000","lastModified":"2026-06-16T21:48:41.527","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A system does not present an appropriate legal message or warning to a user who is accessing it."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*","matchCriteriaId":"4C56F007-5F8E-4BDD-A803-C907BCC0AF55"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.20.1:*:*:*:*:*:*:*","matchCriteriaId":"1E3313D5-52E8-49B3-B145-170D9A26DA43"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*","matchCriteriaId":"4E545C63-FE9C-4CA1-AF0F-D999D84D2AFD"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_95:*:*:*:*:*:*:*:*","matchCriteriaId":"82F7322B-8022-4D0B-ADB3-D0F5B6F20309"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_98:*:gold:*:*:*:*:*:*","matchCriteriaId":"2D3B703C-79B2-4FA2-9E12-713AB977A880"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_nt:3.5.1:*:*:*:*:*:*:*","matchCriteriaId":"D0D4EAC2-A948-461F-B5DD-0AE73CF05D29"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_nt:3.5.1:sp1:*:*:*:*:*:*","matchCriteriaId":"EF8BECF6-3C33-4D8C-B54E-A0D2F3295E81"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_nt:3.5.1:sp2:*:*:*:*:*:*","matchCriteriaId":"828B4519-24D8-45A7-8448-D5FF6C83A2C3"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_nt:3.5.1:sp3:*:*:*:*:*:*","matchCriteriaId":"F495AF7A-CC31-4045-BACC-902950C80ABF"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_nt:3.5.1:sp5:*:*:*:*:*:*","matchCriteriaId":"55A2AC4C-6B85-4B60-BFE1-C9588C5973B0"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_nt:4.0:*:*:*:*:*:*:*","matchCriteriaId":"E53CDA8E-50A8-4509-B070-CCA5604FFB21"}]}]}],"references":[{"url":"http://ciac.llnl.gov/ciac/bulletins/j-043.shtml","source":"cve@mitre.org"},{"url":"http://ciac.llnl.gov/ciac/bulletins/j-043.shtml","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2004-0711","sourceIdentifier":"cve@mitre.org","published":"2004-07-27T04:00:00.000","lastModified":"2026-06-16T22:06:12.807","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"The URL pattern matching feature in BEA WebLogic Server 6.x matches illegal patterns ending in \"*\" as wildcards as if they were the legal \"/*\" pattern, which could cause WebLogic 7.x to allow remote attackers to bypass intended access restrictions because the illegal patterns are properly rejected."},{"lang":"es","value":"La característica de coincidencia de patrones en URL de WebLogic Server 6.x encuentra coincidencias en patrones ilegales terminados en \"*\" como comodines como si fueran el patrón legal \"/\", lo que podría causar que usuarios remotos se saltaran las restricciones de acceso pretendidas porque los patrones ilegales son rechazados adecuadamente."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:*","matchCriteriaId":"F9C5AFCF-79D8-4005-B800-B0C6BD461276"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:7.0:*:express:*:*:*:*:*","matchCriteriaId":"FBDF3AC0-0680-4EEE-898C-47D194667BE2"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:7.0:*:win32:*:*:*:*:*","matchCriteriaId":"8DEDDAF2-555D-4425-B4B6-65B1E9C21FF1"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:7.0:sp1:*:*:*:*:*:*","matchCriteriaId":"6828CE4B-91E8-4688-977F-DC7BC21131C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:7.0:sp1:express:*:*:*:*:*","matchCriteriaId":"BBDB9094-78E8-4CBF-9F5F-321D5174F1EC"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:7.0:sp1:win32:*:*:*:*:*","matchCriteriaId":"9CD2BB36-AC0B-48E9-91E1-A4465896E87A"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:7.0:sp2:*:*:*:*:*:*","matchCriteriaId":"E141AA86-C6D0-4FA8-9268-0FB0635DF9CF"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:7.0:sp2:express:*:*:*:*:*","matchCriteriaId":"6FB8930F-C6D8-40B9-8D08-751F5B47229B"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:7.0:sp2:win32:*:*:*:*:*","matchCriteriaId":"A5C59B80-279B-45B3-9CC1-5A263681025B"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:*","matchCriteriaId":"893D9D88-43C4-4F9F-A364-0585DE6FA9E9"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:7.0:sp3:express:*:*:*:*:*","matchCriteriaId":"D59F9859-7344-43F0-9348-E57FABB9E431"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:7.0:sp3:win32:*:*:*:*:*","matchCriteriaId":"D2D05BAB-AB3B-466E-8301-01A41644DE77"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:7.0:sp4:*:*:*:*:*:*","matchCriteriaId":"D34E2925-DE2A-437F-B349-BD7103F4C37E"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:7.0:sp4:express:*:*:*:*:*","matchCriteriaId":"0A4EC87D-EF83-48C5-B516-A6A482D9F525"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:7.0:sp4:win32:*:*:*:*:*","matchCriteriaId":"935F28E3-9799-4EF6-AB83-62E9C214DD0D"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*","matchCriteriaId":"E08D4CEA-9ACC-4869-BC87-3524A059914F"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:8.1:*:express:*:*:*:*:*","matchCriteriaId":"ADED8968-EA9C-4F0E-AD2F-BC834F4D8A58"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:8.1:*:win32:*:*:*:*:*","matchCriteriaId":"A3DFE048-905E-4890-809D-F6BCEF7F83C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:8.1:sp1:*:*:*:*:*:*","matchCriteriaId":"6F5B2A06-CE19-4A57-9566-09FC1E259CDB"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:8.1:sp1:express:*:*:*:*:*","matchCriteriaId":"F7560131-A6AC-4BBB-AA2D-C7C63AB51226"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:8.1:sp1:win32:*:*:*:*:*","matchCriteriaId":"349036A0-B5E2-4656-8D2D-26BEE9EF9DFB"}]}]}],"references":[{"url":"http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_56.00.jsp","source":"cve@mitre.org"},{"url":"http://www.kb.cert.org/vuls/id/184558","source":"cve@mitre.org","tags":["Third Party Advisory","US Government Resource"]},{"url":"http://www.securityfocus.com/bid/10184","source":"cve@mitre.org","tags":["Patch","Vendor Advisory"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15927","source":"cve@mitre.org"},{"url":"http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_56.00.jsp","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.kb.cert.org/vuls/id/184558","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"]},{"url":"http://www.securityfocus.com/bid/10184","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15927","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2005-1032","sourceIdentifier":"cve@mitre.org","published":"2005-04-06T04:00:00.000","lastModified":"2023-11-07T01:57:22.120","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: cart.php in LiteCommerce might allow remote attackers to obtain sensitive information via invalid (1) category_id or (2) product_id parameters.  NOTE: this issue was originally claimed to be due to SQL injection, but the original researcher is known to be frequently inaccurate with respect to bug type and severity.  The vendor has disputed this issue, saying \"These reports are credited to malicious person we refused to hire. We have not taken legal action against him only because he is located in India.  The vulnerabilites reported can not be reproduced, hence information you provide is contrary to fact.\" Further investigation by CVE personnel shows that an invalid SQL syntax error could be generated, but it only reveals portions of underlying database structure, which is already available in documentation from the vendor, and it does not appear to lead to path disclosure.  Therefore, this issue is not a vulnerability or an exposure, and it probably should be REJECTED"}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2014-7066","sourceIdentifier":"cret@cert.org","published":"2014-10-19T01:55:16.340","lastModified":"2026-06-17T00:14:19.620","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"The LegalEra (aka com.magzter.legalera) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate."},{"lang":"es","value":"La aplicación para Android LegalEra (también conocida como com.magzter.legalera) 3.0 no verifica los certificados X.509 de los servidores SSL, lo que permite a atacantes man-in-the-middle suplantar servidores y obtener información sensible a través de un certificado manipulado."}],"affected":[{"source":"cret@cert.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:A/AC:M/Au:N/C:P/I:P/A:P","baseScore":5.4,"accessVector":"ADJACENT_NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":5.5,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-310"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:magzter:legalera:3:*:*:*:*:android:*:*","matchCriteriaId":"A0EB9B8B-F030-4824-B7E7-5950D93AB340"}]}]}],"references":[{"url":"http://www.kb.cert.org/vuls/id/582497","source":"cret@cert.org","tags":["US Government Resource"]},{"url":"http://www.kb.cert.org/vuls/id/835409","source":"cret@cert.org","tags":["US Government Resource"]},{"url":"https://docs.google.com/spreadsheets/d/1t5GXwjw82SyunALVJb2w0zi3FoLRIkfGPc7AMjRF0r4/edit?usp=sharing","source":"cret@cert.org"},{"url":"http://www.kb.cert.org/vuls/id/582497","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"]},{"url":"http://www.kb.cert.org/vuls/id/835409","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"]},{"url":"https://docs.google.com/spreadsheets/d/1t5GXwjw82SyunALVJb2w0zi3FoLRIkfGPc7AMjRF0r4/edit?usp=sharing","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2015-4412","sourceIdentifier":"cve@mitre.org","published":"2018-02-05T16:29:00.410","lastModified":"2026-06-17T00:27:14.797","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"BSON injection vulnerability in the legal? function in BSON (bson-ruby) gem before 3.0.4 for Ruby allows remote attackers to cause a denial of service (resource consumption) or inject arbitrary data via a crafted string."},{"lang":"es","value":"Vulnerabilidad de inyección BSON en la función legal? en la gema BSON (bson-ruby) en su versión 3.0.4 para Ruby permite que los atacantes remotos provoquen una denegación de servicio (consumo de recursos) o inyecten datos arbitrarios mediante una cadena manipulada."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:bson_project:bson:3.0.3:*:*:*:*:ruby:*:*","matchCriteriaId":"10146522-3ED4-4414-8A7E-A9E47FD673B7"}]}]}],"references":[{"url":"http://www.openwall.com/lists/oss-security/2015/06/06/3","source":"cve@mitre.org","tags":["Mailing List"]},{"url":"http://www.securityfocus.com/bid/75045","source":"cve@mitre.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1229750","source":"cve@mitre.org","tags":["Issue Tracking","Third Party Advisory"]},{"url":"https://github.com/mongodb/bson-ruby/commit/976da329ff03ecdfca3030eb6efe3c85e6db9999","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://github.com/mongodb/bson-ruby/compare/7446d7c6764dfda8dc4480ce16d5c023e74be5ca...28f34978a85b689a4480b4d343389bf4886522e7","source":"cve@mitre.org","tags":["Issue Tracking","Patch","Third Party Advisory"]},{"url":"https://sakurity.com/blog/2015/06/04/mongo_ruby_regexp.html","source":"cve@mitre.org","tags":["Exploit","Patch","Third Party Advisory"]},{"url":"http://www.openwall.com/lists/oss-security/2015/06/06/3","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"]},{"url":"http://www.securityfocus.com/bid/75045","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1229750","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Third Party Advisory"]},{"url":"https://github.com/mongodb/bson-ruby/commit/976da329ff03ecdfca3030eb6efe3c85e6db9999","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://github.com/mongodb/bson-ruby/compare/7446d7c6764dfda8dc4480ce16d5c023e74be5ca...28f34978a85b689a4480b4d343389bf4886522e7","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Third Party Advisory"]},{"url":"https://sakurity.com/blog/2015/06/04/mongo_ruby_regexp.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-9499","sourceIdentifier":"cybersecurity@dahuatech.com","published":"2020-04-09T14:15:13.213","lastModified":"2026-06-17T03:28:04.587","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Some Dahua products have buffer overflow vulnerabilities. After the successful login of the legal account, the attacker sends a specific DDNS test command, which may cause the device to go down."},{"lang":"es","value":"Algunos productos Dahua presentan vulnerabilidades de desbordamiento de búfer. Después del inicio de sesión con éxito de la cuenta legal, el atacante envía un comando de prueba DDNS específico, que puede hacer que el dispositivo se caiga."}],"affected":[{"source":"cybersecurity@dahuatech.com","affectedData":[{"vendor":"n/a","product":"IPC-HX2XXX Series,IPC-HXXX5X4X Series,IPC-HX5842H,IPC-HX7842H,NVR 5x Series,NVR 4x Series,SD6AL Series,SD5A Series,SD1A Series,PTZ1A Series,SD50/52C Series","versions":[{"version":"Versions which Build time before December,2019","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:sd6al_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"B1CE773D-CA5F-483C-B20C-DAD30A590DDD"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:sd6al:-:*:*:*:*:*:*:*","matchCriteriaId":"C35F4371-334B-4EA8-8F48-498C81652F7C"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:sd5a_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"083AE420-CAF9-4A2A-8C76-79DD590FA191"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:sd5a:-:*:*:*:*:*:*:*","matchCriteriaId":"1EE24474-EF35-4475-99DD-4B54D6AF0B2D"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:sd1a_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"9A075994-60D1-40B7-9EF6-8048CBC18764"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:sd1a:-:*:*:*:*:*:*:*","matchCriteriaId":"7A3C5893-E1D0-4E06-9F7F-058B657E4493"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:ptz1a_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"F78D2E9E-9909-4130-A146-CA861F7DF341"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:ptz1a:-:*:*:*:*:*:*:*","matchCriteriaId":"19B57B9D-0729-48E0-892B-E39AE1F89AB4"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:sd50_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"18CD222C-C95A-4D5E-A763-5D2F74EAEC04"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:sd50:-:*:*:*:*:*:*:*","matchCriteriaId":"984AD4D5-D689-4150-A1EE-D48B81CBB7C8"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:sd52c_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"0ECBC0BF-171E-49FD-B6AF-CC7B29D39FB7"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:sd52c:-:*:*:*:*:*:*:*","matchCriteriaId":"5BA0D206-5BE7-4592-8D3E-641F47164770"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:ipc-hx5842h_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"9E8CB654-0526-4E7A-8984-8350B39BB4DF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:ipc-hx5842h:-:*:*:*:*:*:*:*","matchCriteriaId":"724F4B7D-C8C1-4914-B1D6-B4CB9B1F4093"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:ipc-hx7842h_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"3AEBFC1D-9F25-4FDB-A191-D7D6C1C6E234"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:ipc-hx7842h:-:*:*:*:*:*:*:*","matchCriteriaId":"5D6E27D8-C608-49E7-8284-5196EDB428DB"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:ipc-hx2xxx_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"A046C7EA-F954-4F36-9ED3-DBA84F1FB2D3"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:ipc-hx2xxx:-:*:*:*:*:*:*:*","matchCriteriaId":"5B8887C8-C335-4EBB-BC7F-D4F8D8205DAE"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:ipc-hxxx5x4x_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"DCD8DCD2-5CEA-420F-860C-11B469D9FF8F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:ipc-hxxx5x4x:-:*:*:*:*:*:*:*","matchCriteriaId":"F051A1A0-E841-42E7-92A3-E45E4017DCDE"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:n42b1p_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"F092AA97-7184-4499-BB83-D6204BD4621B"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:n42b1p:-:*:*:*:*:*:*:*","matchCriteriaId":"FCB3A7FD-63A2-423C-912F-E2E5B4690CF1"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:n42b2p_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"855B3C5F-CE9D-4FFA-B485-11A8D675F006"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:n42b2p:-:*:*:*:*:*:*:*","matchCriteriaId":"83B0FAFA-BEF4-4196-A4BC-4CFD6DCF4986"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:n42b3p_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"1D0E03DE-1BFA-43AD-9AC6-72A1A1545D4B"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:n42b3p:-:*:*:*:*:*:*:*","matchCriteriaId":"B51E9FED-4929-42CC-AA6F-BFF61E8F88C0"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:n52a4p_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"F20B6467-53DC-4DC6-BCC2-6B6B33ABD65D"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:n52a4p:-:*:*:*:*:*:*:*","matchCriteriaId":"EB41CE1D-1A97-4549-A849-D06F78858CA3"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:n54a4p_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"BFA91720-5AE4-48B6-A940-A4DBE650591D"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahua:n54a4p:-:*:*:*:*:*:*:*","matchCriteriaId":"D871578A-E282-4AEE-8B7E-5F52011FA9CA"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:n52b2p_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"ACD4FD87-1D74-4895-AA89-D26541A55433"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:n52b2p:-:*:*:*:*:*:*:*","matchCriteriaId":"7936F0A3-F6DF-47B2-898E-DBE68B369633"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:n52b5p_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"3D5136C6-2355-4782-BF9C-0874DC5B0CDA"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:n52b5p:-:*:*:*:*:*:*:*","matchCriteriaId":"195D7533-B2EF-4BC2-B6D6-0B141FB90090"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:n52b3p_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"7180D6E1-6F7F-4EAD-BD51-02C029EFB034"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:n52b3p:-:*:*:*:*:*:*:*","matchCriteriaId":"03D1AD58-447D-4D30-B9CF-48B5CB743C2B"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:n54b2p_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"AEC0287A-824B-46D0-84AB-54BEEF90E16B"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:n54b2p:-:*:*:*:*:*:*:*","matchCriteriaId":"5667962D-1A47-4D77-95A4-6B34F8863761"}]}]}],"references":[{"url":"https://www.dahuasecurity.com/support/cybersecurity/details/727","source":"cybersecurity@dahuatech.com","tags":["Vendor Advisory"]},{"url":"https://www.dahuasecurity.com/support/cybersecurity/details/727","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-9500","sourceIdentifier":"cybersecurity@dahuatech.com","published":"2020-04-09T14:15:13.260","lastModified":"2026-06-17T03:28:04.703","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Some products of Dahua have Denial of Service vulnerabilities. After the successful login of the legal account, the attacker sends a specific log query command, which may cause the device to go down."},{"lang":"es","value":"Algunos productos de Dahua presentan vulnerabilidades de denegación de servicio. Después del inicio de sesión con éxito de la cuenta legal, el atacante envía un comando de consulta de registro específico, lo que puede causar que el dispositivo se caiga."}],"affected":[{"source":"cybersecurity@dahuatech.com","affectedData":[{"vendor":"n/a","product":"IPC-HX2XXX Series,IPC-HXXX5X4X Series,IPC-HX5842H,IPC-HX7842H,NVR 5x Series,NVR 4x Series,SD6AL Series,SD5A Series,SD1A Series,PTZ1A Series,SD50/52C Series","versions":[{"version":"Versions which Build time before December,2019","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:sd6al_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"B1CE773D-CA5F-483C-B20C-DAD30A590DDD"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:sd6al:-:*:*:*:*:*:*:*","matchCriteriaId":"C35F4371-334B-4EA8-8F48-498C81652F7C"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:sd5a_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"083AE420-CAF9-4A2A-8C76-79DD590FA191"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:sd5a:-:*:*:*:*:*:*:*","matchCriteriaId":"1EE24474-EF35-4475-99DD-4B54D6AF0B2D"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:sd1a_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"9A075994-60D1-40B7-9EF6-8048CBC18764"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:sd1a:-:*:*:*:*:*:*:*","matchCriteriaId":"7A3C5893-E1D0-4E06-9F7F-058B657E4493"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:ptz1a_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"F78D2E9E-9909-4130-A146-CA861F7DF341"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:ptz1a:-:*:*:*:*:*:*:*","matchCriteriaId":"19B57B9D-0729-48E0-892B-E39AE1F89AB4"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:sd50_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"18CD222C-C95A-4D5E-A763-5D2F74EAEC04"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:sd50:-:*:*:*:*:*:*:*","matchCriteriaId":"984AD4D5-D689-4150-A1EE-D48B81CBB7C8"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:sd52c_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"0ECBC0BF-171E-49FD-B6AF-CC7B29D39FB7"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:sd52c:-:*:*:*:*:*:*:*","matchCriteriaId":"5BA0D206-5BE7-4592-8D3E-641F47164770"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:ipc-hx5842h_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"9E8CB654-0526-4E7A-8984-8350B39BB4DF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:ipc-hx5842h:-:*:*:*:*:*:*:*","matchCriteriaId":"724F4B7D-C8C1-4914-B1D6-B4CB9B1F4093"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:ipc-hx7842h_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"3AEBFC1D-9F25-4FDB-A191-D7D6C1C6E234"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:ipc-hx7842h:-:*:*:*:*:*:*:*","matchCriteriaId":"5D6E27D8-C608-49E7-8284-5196EDB428DB"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:ipc-hx2xxx_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"A046C7EA-F954-4F36-9ED3-DBA84F1FB2D3"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:ipc-hx2xxx:-:*:*:*:*:*:*:*","matchCriteriaId":"5B8887C8-C335-4EBB-BC7F-D4F8D8205DAE"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:ipc-hxxx5x4x_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"DCD8DCD2-5CEA-420F-860C-11B469D9FF8F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:ipc-hxxx5x4x:-:*:*:*:*:*:*:*","matchCriteriaId":"F051A1A0-E841-42E7-92A3-E45E4017DCDE"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:n42b1p_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"F092AA97-7184-4499-BB83-D6204BD4621B"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:n42b1p:-:*:*:*:*:*:*:*","matchCriteriaId":"FCB3A7FD-63A2-423C-912F-E2E5B4690CF1"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:n42b2p_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"855B3C5F-CE9D-4FFA-B485-11A8D675F006"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:n42b2p:-:*:*:*:*:*:*:*","matchCriteriaId":"83B0FAFA-BEF4-4196-A4BC-4CFD6DCF4986"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:n42b3p_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"1D0E03DE-1BFA-43AD-9AC6-72A1A1545D4B"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:n42b3p:-:*:*:*:*:*:*:*","matchCriteriaId":"B51E9FED-4929-42CC-AA6F-BFF61E8F88C0"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:n52a4p_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"F20B6467-53DC-4DC6-BCC2-6B6B33ABD65D"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:n52a4p:-:*:*:*:*:*:*:*","matchCriteriaId":"EB41CE1D-1A97-4549-A849-D06F78858CA3"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:n54a4p_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"BFA91720-5AE4-48B6-A940-A4DBE650591D"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahua:n54a4p:-:*:*:*:*:*:*:*","matchCriteriaId":"D871578A-E282-4AEE-8B7E-5F52011FA9CA"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:n52b2p_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"ACD4FD87-1D74-4895-AA89-D26541A55433"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:n52b2p:-:*:*:*:*:*:*:*","matchCriteriaId":"7936F0A3-F6DF-47B2-898E-DBE68B369633"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:n52b5p_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"3D5136C6-2355-4782-BF9C-0874DC5B0CDA"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:n52b5p:-:*:*:*:*:*:*:*","matchCriteriaId":"195D7533-B2EF-4BC2-B6D6-0B141FB90090"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:n52b3p_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"7180D6E1-6F7F-4EAD-BD51-02C029EFB034"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:n52b3p:-:*:*:*:*:*:*:*","matchCriteriaId":"03D1AD58-447D-4D30-B9CF-48B5CB743C2B"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dahuasecurity:n54b2p_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-12","matchCriteriaId":"AEC0287A-824B-46D0-84AB-54BEEF90E16B"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dahuasecurity:n54b2p:-:*:*:*:*:*:*:*","matchCriteriaId":"5667962D-1A47-4D77-95A4-6B34F8863761"}]}]}],"references":[{"url":"https://www.dahuasecurity.com/support/cybersecurity/details/727","source":"cybersecurity@dahuatech.com","tags":["Vendor Advisory"]},{"url":"https://www.dahuasecurity.com/support/cybersecurity/details/727","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2016-11073","sourceIdentifier":"cve@mitre.org","published":"2020-06-19T20:15:11.397","lastModified":"2026-06-17T00:40:56.720","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting."},{"lang":"es","value":"Se detectó un problema en Mattermost Server versiones anteriores a 3.0.0. Permite un ataque de tipo XSS por medio de una configuración Legal o Support"}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*","versionEndExcluding":"3.0.0","matchCriteriaId":"146D9026-7214-4461-8584-AF9690AC3B2C"}]}]}],"references":[{"url":"https://mattermost.com/security-updates/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://mattermost.com/security-updates/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2021-2273","sourceIdentifier":"secalert_us@oracle.com","published":"2021-04-22T22:15:16.320","lastModified":"2026-06-17T03:49:10.480","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Vulnerability in the Oracle Legal Entity Configurator product of Oracle E-Business Suite (component: Create Contracts). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Legal Entity Configurator. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Legal Entity Configurator accessible data as well as unauthorized access to critical data or complete access to all Oracle Legal Entity Configurator accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)."},{"lang":"es","value":"Una vulnerabilidad en el producto Oracle Legal Entity Configurator de Oracle E-Business Suite (componente: Create Contracts).&#xa0;Las versiones compatibles que están afectadas son 12.1.1-12.1.3.&#xa0;Una vulnerabilidad fácilmente explotable permite a un atacante poco privilegiado con acceso a la red por medio de HTTP comprometer a Oracle Legal Entity Configurator.&#xa0;Los ataques con éxito de esta vulnerabilidad pueden resultar en la creación, eliminación o modificación no autorizada del acceso a datos críticos o a todos los datos accesibles de Oracle Legal Entity Configurator, así como en el acceso no autorizado a datos críticos o acceso completo a todos los datos accesibles de Oracle Legal Entity Configurator.&#xa0;CVSS 3.1 Puntuación Base 8.1 (Impactos en la Confidencialidad e Integridad).&#xa0;CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)"}],"affected":[{"source":"secalert_us@oracle.com","affectedData":[{"vendor":"Oracle Corporation","product":"Legal Entity Configurator","versions":[{"version":"12.1.1-12.1.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert_us@oracle.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-26T14:48:06.754961Z","id":"CVE-2021-2273","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:oracle:legal_entity_configurator:*:*:*:*:*:*:*:*","versionStartIncluding":"12.1.1","versionEndIncluding":"12.1.3","matchCriteriaId":"F3AE1687-CE11-4BAC-BF65-8B6501BDB29B"}]}]}],"references":[{"url":"https://www.oracle.com/security-alerts/cpuapr2021.html","source":"secalert_us@oracle.com","tags":["Patch","Vendor Advisory"]},{"url":"https://www.oracle.com/security-alerts/cpuapr2021.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]}]}}]}