|
222161
|
7.8 |
HIGH
Local
|
trendmicro
|
housecall_for_home_networks
|
A privilege escalation vulnerability in Trend Micro HouseCall for Home Networks (versions below 5.3.0.1063) could be exploited allowing an attacker to place a malicious DLL file into the application …
|
NVD-CWE-noinfo
|
CVE-2019-19688
|
2024-11-21 13:35 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222162
|
7.5 |
HIGH
Network
|
humaxdigital
|
hgb10r-02_firmware
|
An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. Admin credentials are sent over cleartext HTTP.
|
CWE-319 CWE-522
Cleartext Transmission of Sensitive Information Insufficiently Protected Credentials
|
CVE-2019-19890
|
2024-11-21 13:35 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222163
|
7.5 |
HIGH
Network
|
humaxdigital
|
hgb10r-02_firmware
|
An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. The attacker can discover admin credentials in the backup file, aka backupsettings.conf.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-19889
|
2024-11-21 13:35 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222164
|
6.5 |
MEDIUM
Network
|
rockcarry
|
ffjpeg
|
jfif_decode in jfif.c in ffjpeg through 2019-08-21 has a divide-by-zero error.
|
CWE-369
Divide By Zero
|
CVE-2019-19888
|
2024-11-21 13:35 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222165
|
6.5 |
MEDIUM
Network
|
rockcarry
|
ffjpeg
|
bitstr_tell at bitstr.c in ffjpeg through 2019-08-21 has a NULL pointer dereference related to jfif_encode.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-19887
|
2024-11-21 13:35 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222166
|
9.8 |
CRITICAL
Network
|
djangoproject canonical
|
django ubuntu_linux
|
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of…
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2019-19844
|
2024-11-21 13:35 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222167
|
6.5 |
MEDIUM
Network
|
tautulli
|
tautulli
|
In Tautulli 2.1.9, CSRF in the /shutdown URI allows an attacker to shut down the remote media server. (Also, anonymous access can be achieved in applications that do not have a user login area).
|
CWE-352
Origin Validation Error
|
CVE-2019-19833
|
2024-11-21 13:35 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222168
|
8.8 |
HIGH
Network
|
xerox
|
altalink_c8035_firmware
|
Xerox AltaLink C8035 printers allow CSRF. A request to add users is made in the Device User Database form field to the xerox.set URI. (The frmUserName value must have a unique name.)
|
CWE-352
Origin Validation Error
|
CVE-2019-19832
|
2024-11-21 13:35 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222169
|
5.4 |
MEDIUM
Network
|
solarwinds
|
serv-u_ftp_server
|
A cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U FTP Server 15.1.7 in the email parameter, a different vulnerability than CVE-2018-19934 and CVE-2019-13182.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19829
|
2024-11-21 13:35 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222170
|
7.8 |
HIGH
Local
|
shadow_project
|
shadow
|
shadow 4.8, in certain circumstances affecting at least Gentoo, Arch Linux, and Void Linux, allows local users to obtain root access because setuid programs are misconfigured. Specifically, this affe…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-19882
|
2024-11-21 13:35 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|