CVE-2024-35304 – System command injection through Netflow function
https://notcve.org/view.php?id=CVE-2024-35304
System command injection through Netflow function due to improper input validation, allowing attackers to execute arbitrary system commands. This issue affects Pandora FMS: from 700 through <777. • https://pandorafms.com/en/security/common-vulnerabilities-and-exposures • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2018-13144
https://notcve.org/view.php?id=CVE-2018-13144
The transfer and transferFrom functions of a smart contract implementation for Pandora (PDX), an Ethereum token, have an integer overflow. NOTE: this has been disputed by a third party. ** EN DISPUTA ** Las funciones transfer y transferFrom de una implementación de contrato inteligente para Pandora (PDX), un token de Ethereum, tienen un desbordamiento de enteros. NOTA: este dato ha sido impugnado por un tercero • https://github.com/safecomet/EtherTokens/blob/master/Pandora%20%28PDX%29/Pandora%20%28PDX%29.md https://github.com/soohoio/VeriSmartBench/wiki/CVE-False-Reported-Case • CWE-190: Integer Overflow or Wraparound •
CVE-2017-16127
https://notcve.org/view.php?id=CVE-2017-16127
The module pandora-doomsday infects other modules. It's since been unpublished from the registry. El módulo pandora-doomsday infecta a otros módulos. Desde ese momento, se ha retirado del registro. • https://nodesecurity.io/advisories/482 • CWE-276: Incorrect Default Permissions CWE-509: Replicating Malicious Code (Virus or Worm) •
CVE-2017-3194
https://notcve.org/view.php?id=CVE-2017-3194
Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM) attacks. Las versiones anteriores a la 8.3.2 de la app Pandora para iOS no consiguen validar correctamente los certificados SSL proporcionados por las conexiones HTTPS, lo que puede permitir a un atacante realizar ataques Man-in-the-Middle (MitM). • http://www.securityfocus.com/bid/97158 https://exchange.xforce.ibmcloud.com/collection/XFTAS-Daily-Threat-Assessment-for-March-29-2017-0d704f6eb8163d995bbaf57bbf35a018 https://www.kb.cert.org/vuls/id/342303 https://www.scmagazine.com/pandora-apple-app-vulnerable-to-mitm-attacks/article/647106 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-295: Improper Certificate Validation •