|
213021
|
8.8 |
HIGH
Network
|
rdkcentral
|
rdkb_ccsppandm
|
A heap-based buffer over-read in Service_SetParamStringValue in cosa_x_cisco_com_ddns_dml.c of the RDK RDKB-20181217-1 CcspPandM module may allow attackers with login credentials to achieve informati…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-6964
|
2024-11-21 13:47 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213022
|
6.5 |
MEDIUM
Network
|
rdkcentral
|
rdkb_ccsppandm
|
Incorrect access control in actionHandlerUtility.php in the RDK RDKB-20181217-1 WebUI module allows a logged in user to control DDNS, QoS, RIP, and other privileged configurations (intended only for …
|
CWE-862
Missing Authorization
|
CVE-2019-6961
|
2024-11-21 13:47 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213023
|
7.5 |
HIGH
Network
|
tp-link
|
tl-wr1043nd_firmware
|
An issue was discovered on TP-Link TL-WR1043ND V2 devices. The credentials can be easily decoded and cracked by brute-force, WordList, or Rainbow Table attacks. Specifically, credentials in the "Auth…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2019-6972
|
2024-11-21 13:47 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213024
|
9.8 |
CRITICAL
Network
|
tp-link
|
tl-wr1043nd_firmware
|
An issue was discovered on TP-Link TL-WR1043ND V2 devices. An attacker can send a cookie in an HTTP authentication packet to the router management web interface, and fully control the router without …
|
NVD-CWE-noinfo
|
CVE-2019-6971
|
2024-11-21 13:47 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213025
|
7.5 |
HIGH
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite 7.10.1 and earlier allows Information Exposure.
|
NVD-CWE-noinfo
|
CVE-2019-7159
|
2024-11-21 13:47 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213026
|
6.1 |
MEDIUM
Network
|
i-doit
|
i-doit
|
An XSS issue was discovered in i-doit Open 1.12 via the src/tools/php/qr/qr.php url parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-6965
|
2024-11-21 13:47 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213027
|
9.8 |
CRITICAL
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite 7.10.0 and earlier has Incorrect Access Control.
|
NVD-CWE-noinfo
|
CVE-2019-7158
|
2024-11-21 13:47 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213028
|
7.5 |
HIGH
Network
|
genieaccess
|
wip3bvaf_firmware
|
Genie Access WIP3BVAF WISH IP 3MP IR Auto Focus Bullet Camera devices through 3.x are vulnerable to directory traversal via the web interface, as demonstrated by reading /etc/shadow. NOTE: this produ…
|
CWE-22
Path Traversal
|
CVE-2019-7315
|
2024-11-21 13:47 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213029
|
8.8 |
HIGH
Network
|
tp-link
|
tl-wr940n_firmware tl-wr941nd_firmware
|
TP-Link TL-WR940N is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the ipAddrDispose function. By sending specially crafted ICMP echo request packets, a remote au…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-6989
|
2024-11-21 13:47 |
2019-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213030
|
6.5 |
MEDIUM
Network
|
progress
|
sitefinity
|
Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid on the server side. This means the cookie…
|
CWE-613
Insufficient Session Expiration
|
CVE-2019-7215
|
2024-11-21 13:47 |
2019-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|