|
211381
|
3.7 |
LOW
Network
|
w1.fi fedoraproject opensuse debian synology freebsd
|
hostapd wpa_supplicant fedora leap backports_sle debian_linux radius_server router_manager freebsd
|
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD suppo…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-9495
|
2024-11-21 13:51 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211382
|
5.9 |
MEDIUM
Network
|
w1.fi fedoraproject opensuse synology freebsd
|
hostapd wpa_supplicant fedora leap backports_sle radius_server router_manager freebsd
|
The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-9494
|
2024-11-21 13:51 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211383
|
9.8 |
CRITICAL
Network
|
solideos
|
architectural_information_system
|
Architectural Information System 1.0 and earlier versions have a Stack-based buffer overflow, allows remote attackers to execute arbitrary code.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9134
|
2024-11-21 13:51 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211384
|
5.5 |
MEDIUM
Local
|
kmplayer fedoraproject
|
kmplayer fedora
|
When processing subtitles format media file, KMPlayer version 2018.12.24.14 or lower doesn't check object size correctly, which leads to integer underflow then to memory out-of-bound read/write. An a…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2019-9133
|
2024-11-21 13:51 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211385
|
8.8 |
HIGH
Network
|
trendmicro
|
interscan_web_security_virtual_appliance
|
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance version 6.5 SP2 could allow an non-authorized user to disclose administrative credentials. An attacker must be an authenticated…
|
NVD-CWE-noinfo
|
CVE-2019-9490
|
2024-11-21 13:51 |
2019-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211386
|
7.5 |
HIGH
Network
|
trendmicro
|
apex_one apex_one_as_a_service business_security officescan worry-free_business_security
|
A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (versions XG and 11.0), and Worry-Free Business Security (versions 10.0, 9.5 and 9.0) could allow an attacker to modify arbitra…
|
CWE-22
Path Traversal
|
CVE-2019-9489
|
2024-11-21 13:51 |
2019-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211387
|
7.2 |
HIGH
Network
|
postgresql
|
postgresql
|
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's ope…
|
CWE-78
OS Command
|
CVE-2019-9193
|
2024-11-21 13:51 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211388
|
8.8 |
HIGH
Network
|
kakaocorp
|
kakaotalk
|
Remote code execution vulnerability exists in KaKaoTalk PC messenger when user clicks specially crafted link in the message window. This affects KaKaoTalk windows version 2.7.5.2024 or lower.
|
NVD-CWE-noinfo
|
CVE-2019-9132
|
2024-11-21 13:51 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211389
|
5.4 |
MEDIUM
Network
|
online_lottery_php_readymade_script_project
|
online_lottery_php_readymade_script
|
PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Reflected Cross-site Scripting (XSS) via the err value in a .ico picture upload.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9605
|
2024-11-21 13:51 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211390
|
8.8 |
HIGH
Network
|
online_lottery_php_readymade_script_project
|
online_lottery_php_readymade_script
|
PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Cross-Site Request Forgery (CSRF) for Edit Profile actions.
|
CWE-352
Origin Validation Error
|
CVE-2019-9604
|
2024-11-21 13:51 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|