|
223931
|
6.5 |
MEDIUM
Adjacent
|
logitech
|
unifying_receiver_firmware
|
Logitech Unifying devices allow keystroke injection, bypassing encryption. The attacker must press a "magic" key combination while sniffing cryptographic data from a Radio Frequency transmission. NOT…
|
NVD-CWE-noinfo
|
CVE-2019-13053
|
2024-11-21 13:24 |
2019-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223932
|
6.5 |
MEDIUM
Adjacent
|
logitech
|
unifying_receiver_firmware
|
Logitech Unifying devices allow live decryption if the pairing of a keyboard to a receiver is sniffed.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-13052
|
2024-11-21 13:24 |
2019-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223933
|
7.5 |
HIGH
Network
|
gnupg sks_keyserver_project fedoraproject opensuse f5
|
gnupg sks_keyserver fedora leap traffix_signaling_delivery_controller
|
Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the…
|
CWE-295
Improper Certificate Validation
|
CVE-2019-13050
|
2024-11-21 13:24 |
2019-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223934
|
7.8 |
HIGH
Local
|
toaruos_project
|
toaruos
|
An integer wrap in kernel/sys/syscall.c in ToaruOS 1.10.10 allows users to map arbitrary kernel pages into userland process space via TOARU_SYS_FUNC_MMAP, leading to escalation of privileges.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-13049
|
2024-11-21 13:24 |
2019-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223935
|
5.5 |
MEDIUM
Local
|
toaruos_project
|
toaruos
|
kernel/sys/syscall.c in ToaruOS through 1.10.9 allows a denial of service upon a critical error in certain sys_sbrk allocation patterns (involving PAGE_SIZE, and a value less than PAGE_SIZE).
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-13048
|
2024-11-21 13:24 |
2019-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223936
|
7.8 |
HIGH
Local
|
toaruos_project
|
toaruos
|
kernel/sys/syscall.c in ToaruOS through 1.10.9 has incorrect access control in sys_sysfunc case 9 for TOARU_SYS_FUNC_SETHEAP, allowing arbitrary kernel pages to be mapped into user land, leading to r…
|
CWE-862
Missing Authorization
|
CVE-2019-13047
|
2024-11-21 13:24 |
2019-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223937
|
7.8 |
HIGH
Local
|
toaruos_project
|
toaruos
|
linker/linker.c in ToaruOS through 1.10.9 has insecure LD_LIBRARY_PATH handling in setuid applications.
|
CWE-388
7PK - Errors
|
CVE-2019-13046
|
2024-11-21 13:24 |
2019-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223938
|
8.1 |
HIGH
Network
|
irssi
|
irssi
|
Irssi before 1.0.8, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, when SASL is enabled, has a use after free when sending SASL login to the server.
|
CWE-416
Use After Free
|
CVE-2019-13045
|
2024-11-21 13:24 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223939
|
6.1 |
MEDIUM
Network
|
mod_auth_mellon_project oracle fedoraproject canonical
|
mod_auth_mellon zfs_storage_appliance_kit fedora ubuntu_linux
|
mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL.
|
CWE-601
Open Redirect
|
CVE-2019-13038
|
2024-11-21 13:24 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223940
|
7.8 |
HIGH
Local
|
pandorafms
|
pandora_fms
|
Artica Pandora FMS 7.0 NG before 735 suffers from local privilege escalation due to improper permissions on C:\PandoraFMS and its sub-folders, allowing standard users to create new files. Moreover, t…
|
NVD-CWE-noinfo
|
CVE-2019-13035
|
2024-11-21 13:24 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|