CVE-2021-36385
Published Aug 24, 2021A SQL Injection vulnerability in Cerner Mobile Care 5.0.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via a Fullwidth Apostrophe (aka U+FF07) in the…
Vendor archive
7 CVEs tagged to vendor cerner — 2 Critical, 5 High, 0 Medium, 0 Low, 0 Unrated.
A SQL Injection vulnerability in Cerner Mobile Care 5.0.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via a Fullwidth Apostrophe (aka U+FF07) in the…
Cerner medico 26.00 has a Local Buffer Overflow (issue 3 of 3).
Cerner medico 26.00 has a Local Buffer Overflow (issue 2 of 3).
Cerner medico 26.00 has a Local Buffer Overflow (issue 1 of 3).
Cerner medico 26.00 allows variable reuse, possibly causing data corruption.
An issue was discovered on Cerner Connectivity Engine (CCE) 4 devices. The hostname, timezone, and NTP server configurations on the CCE device are vulnerable to command injection…
An issue was discovered on Cerner Connectivity Engine (CCE) 4 devices. The user running the main CCE firmware has NOPASSWD sudo privileges to several utilities that could be used…