Vulnerabilities > Verizon
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-06-01 | CVE-2020-7660 | Deserialization of Untrusted Data vulnerability in Verizon Serialize-Javascript serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js". | 8.1 |
2019-12-05 | CVE-2019-16769 | Cross-site Scripting vulnerability in Verizon Serialize-Javascript The serialize-javascript npm package before version 2.1.1 is vulnerable to Cross-site Scripting (XSS). | 5.4 |
2019-04-11 | CVE-2019-3916 | Forced Browsing vulnerability in Verizon Fios Quantum Gateway G1100 Firmware 02.01.00.05 Information disclosure vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an remote, unauthenticated attacker to retrieve the value of the password salt by simply requesting an API URL in a web browser (e.g. | 7.5 |
2019-04-11 | CVE-2019-3915 | Authentication Bypass by Capture-replay vulnerability in Verizon Fios Quantum Gateway G1100 Firmware 02.01.00.05 Authentication Bypass by Capture-replay vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an unauthenticated attacker with adjacent network access to intercept and replay login requests to gain access to the administrative web interface. | 7.5 |
2019-04-11 | CVE-2019-3914 | OS Command Injection vulnerability in Verizon Fios Quantum Gateway G1100 Firmware 02.01.00.05 Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a remote, authenticated attacker to execute arbitrary commands on the target device by adding an access control rule for a network object with a crafted hostname. | 7.2 |