|
211491
|
6.1 |
MEDIUM
Network
|
hsycms
|
hsycms
|
An issue was discovered in Hsycms V1.1. There is an XSS vulnerability via the name field to the /book page.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9145
|
2024-11-21 13:51 |
2019-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211492
|
8.8 |
HIGH
Network
|
exiv2
|
exiv2
|
An issue was discovered in Exiv2 0.27. There is infinite recursion at BigTiffImage::printIFD in the file bigtiffimage.cpp. This can be triggered by a crafted file. It allows an attacker to cause Deni…
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-9144
|
2024-11-21 13:51 |
2019-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211493
|
8.8 |
HIGH
Network
|
exiv2
|
exiv2
|
An issue was discovered in Exiv2 0.27. There is infinite recursion at Exiv2::Image::printTiffStructure in the file image.cpp. This can be triggered by a crafted file. It allows an attacker to cause D…
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-9143
|
2024-11-21 13:51 |
2019-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211494
|
6.1 |
MEDIUM
Network
|
b3log
|
symphony
|
An issue was discovered in b3log Symphony (aka Sym) before v3.4.7. XSS exists via the userIntro and userNickname fields to processor/SettingsProcessor.java.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9142
|
2024-11-21 13:51 |
2019-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211495
|
7.5 |
HIGH
Network
|
dlink
|
dir-825_rev.b_firmware
|
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. There is an information disclosure vulnerability via requests for the router_info.xml document. This will reveal the PIN code, MAC addres…
|
CWE-200
Information Exposure
|
CVE-2019-9126
|
2024-11-21 13:51 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211496
|
9.8 |
CRITICAL
Network
|
d-link
|
dir-878_firmware
|
An issue was discovered on D-Link DIR-878 1.12B01 devices. Because strncpy is misused, there is a stack-based buffer overflow vulnerability that does not require authentication via the HNAP_AUTH HTTP…
|
CWE-787 CWE-306
Out-of-bounds Write Missing Authentication for Critical Function
|
CVE-2019-9125
|
2024-11-21 13:51 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211497
|
9.8 |
CRITICAL
Network
|
d-link
|
dir-878_firmware
|
An issue was discovered on D-Link DIR-878 1.12B01 devices. At the /HNAP1 URI, an attacker can log in with a blank password.
|
CWE-287
Improper Authentication
|
CVE-2019-9124
|
2024-11-21 13:51 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211498
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-825_rev.b_firmware
|
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. The "user" account has a blank password.
|
CWE-521
Weak Password Requirements
|
CVE-2019-9123
|
2024-11-21 13:51 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211499
|
7.8 |
HIGH
Local
|
sublimetext
|
sublime_text_3
|
DLL hijacking is possible in Sublime Text 3 version 3.1.1 build 3176 on 32-bit Windows platforms because a Trojan horse api-ms-win-core-fibers-l1-1-1.dll or api-ms-win-core-localization-l1-2-1.dll fi…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-9116
|
2024-11-21 13:51 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211500
|
8.8 |
HIGH
Network
|
dlink
|
dir-825_rev.b_firmware
|
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the ntp_server parameter in an ntp_sync.cgi POST request.
|
NVD-CWE-noinfo
|
CVE-2019-9122
|
2024-11-21 13:51 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|