|
223041
|
5.3 |
MEDIUM
Network
|
honeywell
|
hbd3pr2_firmware h4d3prv3_firmware hed3pr3_firmware h4d3prv2_firmware hbd3pr1_firmware h4w8pr2_firmware hbw8pr2_firmware h2w2pc1m_firmware h2w4per3_firmware h2w2per3_firmwa…
|
In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data in JSON format for IP cameras…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-13523
|
2024-11-21 13:25 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223042
|
6.3 |
MEDIUM
Local
|
canonical opensuse libgcrypt20_project
|
ubuntu_linux leap libgcrypt20
|
It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-13627
|
2024-11-21 13:25 |
2019-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223043
|
4.4 |
MEDIUM
Local
|
tridium
|
niagara_ax niagara4
|
A specific utility may allow an attacker to gain read access to privileged files in the Niagara AX 3.8u4 (JACE 3e, JACE 6e, JACE 7, JACE-8000), Niagara 4.4u3 (JACE 3e, JACE 6e, JACE 7, JACE-8000), an…
|
NVD-CWE-noinfo
|
CVE-2019-13528
|
2024-11-21 13:25 |
2019-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223044
|
7.8 |
HIGH
Local
|
rockwellautomation
|
arena_simulation_software
|
In Rockwell Automation Arena Simulation Software Cat. 9502-Ax, Versions 16.00.00 and earlier, a maliciously crafted Arena file opened by an unsuspecting user may result in the use of a pointer that h…
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2019-13527
|
2024-11-21 13:25 |
2019-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223045
|
9.8 |
CRITICAL
Network
|
advantech
|
webaccess
|
In WebAccess versions 8.4.1 and prior, an exploit executed over the network may cause improper control of generation of code, which may allow remote code execution, data exfiltration, or cause a syst…
|
CWE-94
Code Injection
|
CVE-2019-13558
|
2024-11-21 13:25 |
2019-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223046
|
8.8 |
HIGH
Network
|
advantech
|
webaccess
|
In WebAccess versions 8.4.1 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack of proper validation of the length of user-supplied data. Exploitation of these vulner…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13556
|
2024-11-21 13:25 |
2019-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223047
|
8.8 |
HIGH
Network
|
advantech
|
webaccess
|
In WebAccess versions 8.4.1 and prior, multiple command injection vulnerabilities are caused by a lack of proper validation of user-supplied data and may allow arbitrary file deletion and remote code…
|
CWE-77
Command Injection
|
CVE-2019-13552
|
2024-11-21 13:25 |
2019-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223048
|
9.8 |
CRITICAL
Network
|
advantech
|
webaccess
|
In WebAccess, versions 8.4.1 and prior, an improper authorization vulnerability may allow an attacker to disclose sensitive information, cause improper control of generation of code, which may allow …
|
NVD-CWE-Other
|
CVE-2019-13550
|
2024-11-21 13:25 |
2019-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223049
|
8.6 |
HIGH
Local
|
codesys
|
codesys
|
3S-Smart Software Solutions GmbH CODESYS V3 Library Manager, all versions prior to 3.5.16.0, allows the system to display active library content without checking its validity, which may allow the con…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13538
|
2024-11-21 13:25 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223050
|
6.5 |
MEDIUM
Network
|
codesys
|
control_for_beaglebone control_for_empc-a\/imx6 control_for_iot2000 control_for_pfc100 control_for_pfc200 control_for_raspberry_pi control_rte control_win linux runtime_sys…
|
3S-Smart Software Solutions GmbH CODESYS V3 OPC UA Server, all versions 3.5.11.0 to 3.5.15.0, allows an attacker to send crafted requests from a trusted OPC UA client that cause a NULL pointer derefe…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-13542
|
2024-11-21 13:25 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|