Vulnerabilities > Hughes

DATE CVE VULNERABILITY TITLE RISK
2023-01-26 CVE-2023-22971 Cross-site Scripting vulnerability in Hughes products
Cross Site Scripting (XSS) vulnerability in Hughes Network Systems Router Terminal for HX200 v8.3.1.14, HX90 v6.11.0.5, HX50L v6.10.0.18, HN9460 v8.2.0.48, and HN7000S v6.9.0.37, allows unauthenticated attackers to misuse frames, include JS/HTML code and steal sensitive information from legitimate users of the application.
network
low complexity
hughes CWE-79
6.1
2018-07-13 CVE-2016-9497 Improper Authentication vulnerability in Hughes products
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, is vulnerable to an authentication bypass using an alternate path or channel.
low complexity
hughes CWE-287
8.3
2018-07-13 CVE-2016-9496 Missing Authentication for Critical Function vulnerability in Hughes products
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, lacks authentication.
low complexity
hughes CWE-306
6.1
2018-07-13 CVE-2016-9495 Use of Hard-coded Credentials vulnerability in Hughes products
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, uses hard coded credentials.
low complexity
hughes CWE-798
5.8
2018-07-13 CVE-2016-9494 Improper Input Validation vulnerability in Hughes products
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, are potentially vulnerable to improper input validation.
low complexity
hughes CWE-20
3.3
2001-12-26 CVE-2001-1225 Denial of Service vulnerability in Hughes Msql 2.0.10/2.0.11/2.0.12
Hughes Technology Mini SQL 2.0.10 through 2.0.12 allows local users to cause a denial of service by creating a very large array in a table, which causes miniSQL to crash when the table is queried.
local
low complexity
hughes
2.1
1999-12-27 CVE-2000-0012 Unspecified vulnerability in Hughes Msql 2.0.11
Buffer overflow in w3-msql CGI program in miniSQL package allows remote attackers to execute commands.
network
low complexity
hughes
critical
10.0
1999-08-17 CVE-1999-0753 Unspecified vulnerability in Hughes Msql 2.0/2.0.10
The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories.
network
low complexity
hughes
7.5
1999-02-15 CVE-1999-1260 Unspecified vulnerability in Hughes Msql
mSQL (Mini SQL) 2.0.6 allows remote attackers to obtain sensitive server information such as logged users, database names, and server version via the ServerStats query.
network
low complexity
hughes
7.5
1999-01-01 CVE-1999-0276 Unspecified vulnerability in Hughes Msql 2.0./2.0.1
mSQL v2.0.1 and below allows remote execution through a buffer overflow.
network
low complexity
hughes
7.5