|
222721
|
9.8 |
CRITICAL
Network
|
mediatek
|
mt8163_firmware mt6625_firmware mt6577_firmware
|
The MediaTek Embedded Multimedia Card (eMMC) subsystem for Android on MT65xx, MT66xx, and MT8163 SoC devices allows attackers to execute arbitrary commands as root via shell metacharacters in a filen…
|
CWE-78
OS Command
|
CVE-2019-15027
|
2024-11-21 13:27 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222722
|
5.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms.
|
NVD-CWE-noinfo
|
CVE-2019-15028
|
2024-11-21 13:27 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222723
|
9.8 |
CRITICAL
Network
|
golang debian
|
go debian_linux
|
net/url in Go before 1.11.13 and 1.12.x before 1.12.8 mishandles malformed hosts in URLs, leading to an authorization bypass in some applications. This is related to a Host field with a suffix appear…
|
NVD-CWE-noinfo
|
CVE-2019-14809
|
2024-11-21 13:27 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222724
|
8.1 |
HIGH
Network
|
eq-3
|
homematic_ccu2_firmware homematic_ccu3_firmware
|
eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn before 2.3.0 installed allow administrative operations by unauthenticated attackers with access to the web interface, because features such as File-Br…
|
NVD-CWE-noinfo
|
CVE-2019-14986
|
2024-11-21 13:27 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222725
|
9.8 |
CRITICAL
Network
|
eq-3
|
homematic_ccu2_firmware homematic_ccu3_firmware
|
eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface, because this interface can access the CMD_EXEC vi…
|
CWE-287
Improper Authentication
|
CVE-2019-14985
|
2024-11-21 13:27 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222726
|
8.1 |
HIGH
Network
|
eq-3
|
homematic_ccu2_firmware homematic_ccu3_firmware
|
eQ-3 Homematic CCU2 and CCU3 with the XML-API through 1.2.0 AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface, because the undocumented addons/…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-14984
|
2024-11-21 13:27 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222727
|
7.5 |
HIGH
Network
|
istio
|
istio
|
Istio before 1.1.13 and 1.2.x before 1.2.4 mishandles regular expressions for long URIs, leading to a denial of service during use of the JWT, VirtualService, HTTPAPISpecBinding, or QuotaSpecBinding …
|
CWE-185
Incorrect Regular Expression
|
CVE-2019-14993
|
2024-11-21 13:27 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222728
|
4.8 |
MEDIUM
Network
|
schben
|
framework
|
Adive Framework through 2.0.7 is affected by XSS in the Create New Table and Create New Navigation Link functions.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14987
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222729
|
6.5 |
MEDIUM
Network
|
exiv2
|
exiv2
|
In Exiv2 before v0.27.2, there is an integer overflow vulnerability in the WebPImage::getHeaderOffset function in webpimage.cpp. It can lead to a buffer overflow vulnerability and a crash.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-14982
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222730
|
6.5 |
MEDIUM
Network
|
imagemagick debian canonical opensuse
|
imagemagick debian_linux ubuntu_linux leap
|
In ImageMagick 7.x before 7.0.8-41 and 6.x before 6.9.10-41, there is a divide-by-zero vulnerability in the MeanShiftImage function. It allows an attacker to cause a denial of service by sending a cr…
|
CWE-369
Divide By Zero
|
CVE-2019-14981
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|