|
222801
|
8.8 |
HIGH
Network
|
libssh2 fedoraproject debian netapp redhat opensuse apple oracle
|
libssh2 fedora debian_linux ontap_select_deploy_administration_utility enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus
|
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the server. A remote attacker who compromises a SSH server …
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2019-3855
|
2024-11-21 13:42 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222802
|
9.1 |
CRITICAL
Network
|
libssh2 fedoraproject debian netapp opensuse
|
libssh2 fedora debian_linux ontap_select_deploy_administration_utility leap
|
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-3862
|
2024-11-21 13:42 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222803
|
9.1 |
CRITICAL
Network
|
libssh2 fedoraproject debian netapp opensuse
|
libssh2 fedora debian_linux ontap_select_deploy_administration_utility leap
|
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote attacker who compromises a SSH server may be able to …
|
CWE-125
Out-of-bounds Read
|
CVE-2019-3859
|
2024-11-21 13:42 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222804
|
5.5 |
MEDIUM
Local
|
libsndfile_project debian canonical
|
libsndfile debian_linux ubuntu_linux
|
It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of a buffer in wav_write_header() function in wav.c. A local attacker may use this…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-3832
|
2024-11-21 13:42 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222805
|
8.8 |
HIGH
Network
|
indionetworks
|
unibox_firmware
|
An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. The tools/ping Ping feature of the Diagnostic Tools component is vulnerable to Remote Command Execution, allowing an at…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-3497
|
2024-11-21 13:42 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222806
|
8.8 |
HIGH
Network
|
indionetworks
|
unibox_firmware
|
An issue was discovered on Wifi-soft UniBox controller 3.x devices. The tools/controller/diagnostic_tools_controller Diagnostic Tools Controller is vulnerable to Remote Command Execution, allowing an…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-3496
|
2024-11-21 13:42 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222807
|
8.8 |
HIGH
Network
|
indionetworks
|
unibox_firmware
|
An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. network/mesh/edit-nds.php is vulnerable to arbitrary file upload, allowing an attacker to upload .php files and execute…
|
CWE-798 CWE-434
Use of Hard-coded Credentials Unrestricted Upload of File with Dangerous Type
|
CVE-2019-3495
|
2024-11-21 13:42 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222808
|
7.5 |
HIGH
Network
|
openwsman_project fedoraproject opensuse
|
openwsman fedora leap
|
Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in process_connection() when parsing specially crafted HTTP requests. A remote, unauthenticated attacker can exploit thi…
|
-
|
CVE-2019-3833
|
2024-11-21 13:42 |
2019-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222809
|
7.5 |
HIGH
Network
|
openwsman_project redhat fedoraproject opensuse
|
openwsman enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_eus enterprise_linux_server_aus enterp…
|
Openwsman, versions up to and including 2.6.9, are vulnerable to arbitrary file disclosure because the working directory of openwsmand daemon was set to root directory. A remote, unauthenticated atta…
|
-
|
CVE-2019-3816
|
2024-11-21 13:42 |
2019-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222810
|
8.1 |
HIGH
Network
|
cloudfoundry
|
capi-release
|
Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with read permissions can request package information …
|
CWE-269
Improper Privilege Management
|
CVE-2019-3785
|
2024-11-21 13:42 |
2019-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|