|
222411
|
7.5 |
HIGH
Network
|
mi
|
dgnwg03lm_firmware zncz03lm_firmware mccgq01lm_firmware wsdcgq01lm_firmware rtcgq01lm_firmware
|
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attack…
|
CWE-20
Improper Input Validation
|
CVE-2019-15914
|
2024-11-21 13:29 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222412
|
9.8 |
CRITICAL
Network
|
mi
|
dgnwg03lm_firmware zncz03lm_firmware mccgq01lm_firmware wsdcgq01lm_firmware rtcgq01lm_firmware
|
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Because of insecure key transport in ZigBee communication, causing attackers to gain sensitive informa…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-15913
|
2024-11-21 13:29 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222413
|
7.5 |
HIGH
Network
|
asus
|
hg100_firmware mw100_firmware ws-101_firmware ts-101_firmware as-101_firmware ms-101_firmware dl-101_firmware
|
An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of …
|
CWE-20
Improper Input Validation
|
CVE-2019-15912
|
2024-11-21 13:29 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222414
|
9.8 |
CRITICAL
Network
|
asus
|
hg100_firmware mw100_firmware ws-101_firmware ts-101_firmware as-101_firmware ms-101_firmware dl-101_firmware
|
An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Because of insecure key transport in ZigBee communication, attackers can obtain sensitiv…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-15911
|
2024-11-21 13:29 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222415
|
7.5 |
HIGH
Network
|
asus
|
hg100_firmware mw100_firmware ws-101_firmware ts-101_firmware as-101_firmware ms-101_firmware dl-101_firmware
|
An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can utilize the "discover ZigBee network procedure" to perform a denial of ser…
|
CWE-20
Improper Input Validation
|
CVE-2019-15910
|
2024-11-21 13:29 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222416
|
7.5 |
HIGH
Network
|
http_server_project
|
http_server
|
A Path traversal exists in http_server which allows an attacker to read arbitrary system files.
|
CWE-22
Path Traversal
|
CVE-2019-15600
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222417
|
9.8 |
CRITICAL
Network
|
tree-kill_project
|
tree-kill
|
A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
|
CWE-94
Code Injection
|
CVE-2019-15599
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222418
|
9.8 |
CRITICAL
Network
|
treekill_project
|
treekill
|
A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
|
CWE-78
OS Command
|
CVE-2019-15598
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222419
|
9.8 |
CRITICAL
Network
|
node-df_project
|
node-df
|
A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.
|
CWE-94
Code Injection
|
CVE-2019-15597
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222420
|
7.5 |
HIGH
Network
|
statics-server_project
|
statics-server
|
A path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a symlink is used within the working directory.
|
CWE-22
Path Traversal
|
CVE-2019-15596
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|