|
224081
|
7.5 |
HIGH
Network
|
3cx
|
3cx
|
An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2. The Content.MainForm.wgx component is affected by XXE via a crafted XML document in POST dat…
|
CWE-611
XXE
|
CVE-2019-13176
|
2024-11-21 13:24 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224082
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-600m_firmware
|
An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-13101
|
2024-11-21 13:24 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224083
|
7.8 |
HIGH
Local
|
denx opensuse
|
u-boot leap
|
Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stack buffer overflow and likely code execution.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13106
|
2024-11-21 13:24 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224084
|
7.8 |
HIGH
Local
|
denx
|
u-boot
|
Das U-Boot versions 2019.07-rc1 through 2019.07-rc4 can double-free a cached block of data when listing files in a crafted ext4 filesystem.
|
CWE-415
Double Free
|
CVE-2019-13105
|
2024-11-21 13:24 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224085
|
7.8 |
HIGH
Local
|
denx opensuse
|
u-boot leap
|
In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite a very large amount of data (including the whole stack) while reading a crafted ext4 filesystem.
|
CWE-787 CWE-191
Out-of-bounds Write Integer Underflow (Wrap or Wraparound)
|
CVE-2019-13104
|
2024-11-21 13:24 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224086
|
9.8 |
CRITICAL
Network
|
shenzhen_dragon_brothers
|
fb50_firmware
|
An HTTP parameter pollution issue was discovered on Shenzhen Dragon Brothers Fingerprint Bluetooth Round Padlock FB50 2.3. With the user ID, user name, and the lock's MAC address, anyone can unbind t…
|
CWE-20
Improper Input Validation
|
CVE-2019-13143
|
2024-11-21 13:24 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224087
|
9.8 |
CRITICAL
Network
|
oxid-esales
|
eshop
|
OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by an attacker. This includes all shopping cart options, customer data, and the dat…
|
CWE-89
SQL Injection
|
CVE-2019-13026
|
2024-11-21 13:24 |
2019-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224088
|
7.5 |
HIGH
Network
|
nats
|
nats_server
|
An integer overflow in NATS Server before 2.0.2 allows a remote attacker to crash the server by sending a crafted request. If authentication is enabled, then the remote attacker must have first authe…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-13126
|
2024-11-21 13:24 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224089
|
7.1 |
HIGH
Local
|
denx
|
u-boot
|
A crafted self-referential DOS partition table will cause all Das U-Boot versions through 2019.07-rc4 to infinitely recurse, causing the stack to grow infinitely and eventually either crash or overwr…
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-13103
|
2024-11-21 13:24 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224090
|
6.1 |
MEDIUM
Network
|
control-webpanel
|
webpanel
|
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, Reflected XSS in filemanager2.php (parameter fm_current_dir) allows attackers to steal a cookie or session, or redirect to a phishing webs…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13387
|
2024-11-21 13:24 |
2019-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|