Vulnerabilities > Axis > 2420 Network Camera > 2.40

DATE CVE VULNERABILITY TITLE RISK
2004-12-31 CVE-2004-2427 Denial-Of-Service vulnerability in 2420 Video Server
Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to obtain sensitive information via direct requests to (1) admin/getparam.cgi, (2) admin/systemlog.cgi, (3) admin/serverreport.cgi, and (4) admin/paramlist.cgi, modify system information via (5) setparam.cgi and (6) factorydefault.cgi, or (7) cause a denial of service (reboot) via restart.cgi.
network
low complexity
axis
critical
10.0
2004-12-31 CVE-2004-2426 Multiple vulnerability in Axis Network Camera And Video Server
Directory traversal vulnerability in Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to bypass authentication via a ..
network
low complexity
axis
5.0
2004-12-31 CVE-2004-2425 Multiple vulnerability in Axis Network Camera And Video Server
Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and possibly other shell metacharacters in the query string to virtualinput.cgi.
network
low complexity
axis
7.5
2004-12-31 CVE-2004-0789 Denial Of Service vulnerability in Multiple Vendor DNS Response Flooding
Multiple implementations of the DNS protocol, including (1) Poslib 1.0.2-1 and earlier as used by Posadis, (2) Axis Network products before firmware 3.13, and (3) Men & Mice Suite 2.2x before 2.2.3 and 3.5.x before 3.5.2, allow remote attackers to cause a denial of service (CPU and network bandwidth consumption) by triggering a communications loop via (a) DNS query packets with localhost as a spoofed source address, or (b) a response packet that triggers a response packet.
5.0