|
223791
|
9.8 |
CRITICAL
Network
|
strong_password_project
|
strong_password
|
The strong_password gem 0.0.7 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 0.0.6.
|
CWE-94
Code Injection
|
CVE-2019-13354
|
2024-11-21 13:24 |
2019-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223792
|
7.8 |
HIGH
Local
|
python
|
python
|
The MSI installer for Python through 2.7.16 on Windows defaults to the C:\Python27 directory, which makes it easier for local users to deploy Trojan horse code. (This also affects old 3.x releases be…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2019-13404
|
2024-11-21 13:24 |
2019-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223793
|
8.8 |
HIGH
Network
|
fortinet
|
fcm-mb40_firmware
|
/usr/sbin/default.sh and /usr/apache/htdocs/cgi-bin/admin/hardfactorydefault.cgi on Dynacolor FCM-MB40 v1.2.0.0 devices implement an incomplete factory-reset process. A backdoor can persist because n…
|
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
|
CVE-2019-13402
|
2024-11-21 13:24 |
2019-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223794
|
8.8 |
HIGH
Network
|
fortinet
|
fcm-mb40_firmware
|
Dynacolor FCM-MB40 v1.2.0.0 devices have CSRF in all scripts under cgi-bin/.
|
CWE-352
Origin Validation Error
|
CVE-2019-13401
|
2024-11-21 13:24 |
2019-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223795
|
9.8 |
CRITICAL
Network
|
fortinet
|
fcm-mb40_firmware
|
Dynacolor FCM-MB40 v1.2.0.0 use /etc/appWeb/appweb.pass to store administrative web-interface credentials in cleartext. These credentials can be retrieved via cgi-bin/getuserinfo.cgi?mode=info.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-13400
|
2024-11-21 13:24 |
2019-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223796
|
5.9 |
MEDIUM
Network
|
fortinet
|
fcm-mb40_firmware
|
Dynacolor FCM-MB40 v1.2.0.0 devices have a hard-coded SSL/TLS key that is used during an administrator's SSL conversation.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-13399
|
2024-11-21 13:24 |
2019-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223797
|
7.2 |
HIGH
Network
|
fortinet
|
fcm-mb40_firmware
|
Dynacolor FCM-MB40 v1.2.0.0 devices allow remote attackers to execute arbitrary commands via a crafted parameter to a CGI script, as demonstrated by sed injection in cgi-bin/camctrl_save_profile.cgi …
|
CWE-78
OS Command
|
CVE-2019-13398
|
2024-11-21 13:24 |
2019-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223798
|
8.8 |
HIGH
Network
|
imagemagick
|
imagemagick
|
In ImageMagick 7.0.8-50 Q16, ComplexImages in MagickCore/fourier.c has a heap-based buffer over-read because of incorrect calls to GetCacheViewVirtualPixels.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-13391
|
2024-11-21 13:24 |
2019-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223799
|
6.5 |
MEDIUM
Network
|
ffmpeg
|
ffmpeg
|
In FFmpeg 4.1.3, there is a division by zero at adx_write_trailer in libavformat/rawenc.c.
|
CWE-369
Divide By Zero
|
CVE-2019-13390
|
2024-11-21 13:24 |
2019-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223800
|
8.8 |
HIGH
Network
|
avtech
|
room_alert_3e_firmware
|
On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?actio…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2019-13379
|
2024-11-21 13:24 |
2019-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|