|
213071
|
7.5 |
HIGH
Network
|
logmx
|
logmx
|
GUP (generic update process) in LightySoft LogMX before 7.4.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan hor…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-7323
|
2024-11-21 13:48 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213072
|
5.3 |
MEDIUM
Network
|
libpng debian canonical oracle hpe hp mozilla opensuse netapp redhat
|
libpng debian_linux ubuntu_linux jdk java_se mysql hyperion_infrastructure_technology xp7_command_view_advanced_edition_suite xp7_command_view firefox thunderbird lea…
|
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
|
CWE-416
Use After Free
|
CVE-2019-7317
|
2024-11-21 13:48 |
2019-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213073
|
7.8 |
HIGH
Local
|
schneider-electric
|
software_update
|
A CWE-502: Deserialization of Untrusted Data vulnerability exists which could allow an attacker to execute arbitrary code on the targeted system with SYSTEM privileges when placing a malicious user t…
|
-
|
CVE-2019-6834
|
2024-11-21 13:47 |
2022-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213074
|
9.8 |
CRITICAL
Network
|
qnap
|
quts_hero qts
|
This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS …
|
CWE-77
Command Injection
|
CVE-2019-7198
|
2024-11-21 13:47 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213075
|
6.5 |
MEDIUM
Network
|
apple
|
airport_base_station_firmware
|
A denial of service issue was addressed with improved memory handling. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. An attacker in a …
|
NVD-CWE-noinfo
|
CVE-2019-7291
|
2024-11-21 13:47 |
2020-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213076
|
9.8 |
CRITICAL
Network
|
apple
|
mac_os_x iphone_os
|
The issue was addressed with improved validation on the FaceTime server. This issue is fixed in macOS Mojave 10.14.3 Supplemental Update, iOS 12.1.4. A thorough security audit of the FaceTime service…
|
NVD-CWE-noinfo
|
CVE-2019-7288
|
2024-11-21 13:47 |
2020-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213077
|
7.2 |
HIGH
Network
|
pexip
|
pexip_infinity
|
Pexip Infinity before 20.1 allows privilege escalation by restoring a system backup.
|
CWE-20
Improper Input Validation
|
CVE-2019-7178
|
2024-11-21 13:47 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213078
|
7.2 |
HIGH
Network
|
pexip
|
pexip_infinity
|
Pexip Infinity before 20.1 allows Code Injection onto nodes via an admin.
|
CWE-94
Code Injection
|
CVE-2019-7177
|
2024-11-21 13:47 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213079
|
7.5 |
HIGH
Network
|
avaya
|
ip_office
|
A vulnerability was discovered in the web interface component of IP Office that may potentially allow a remote, unauthenticated user with network access to gain sensitive information. Affected versio…
|
NVD-CWE-noinfo
|
CVE-2019-7005
|
2024-11-21 13:47 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213080
|
9.8 |
CRITICAL
Network
|
amd
|
overdrive
|
An issue was discovered in AODDriver2.sys in AMD OverDrive. The vulnerable driver exposes a wrmsr instruction via IOCTL 0x81112ee0 and does not properly filter the Model Specific Register (MSR). Allo…
|
NVD-CWE-noinfo
|
CVE-2019-7247
|
2024-11-21 13:47 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|