|
223371
|
6.5 |
MEDIUM
Network
|
digium
|
asterisk
|
res_pjsip_t38 in Sangoma Asterisk 15.x before 15.7.4 and 16.x before 16.5.1 allows an attacker to trigger a crash by sending a declined stream in a response to a T.38 re-invite initiated by Asterisk.…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-15297
|
2024-11-21 13:28 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223372
|
6.5 |
MEDIUM
Network
|
if.svnadmin_project
|
if.svnadmin
|
iF.SVNAdmin through 1.6.2 allows svnadmin/usercreate.php CSRF to create a user.
|
CWE-352
Origin Validation Error
|
CVE-2019-15128
|
2024-11-21 13:28 |
2019-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223373
|
9.8 |
CRITICAL
Network
|
sahipro
|
sahi_pro
|
An issue was discovered in Tyto Sahi Pro 6.x through 8.0.0. TestRunner_Non_distributed (and distributed end points) does not have any authentication mechanism. This allow an attacker to execute an ar…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-15102
|
2024-11-21 13:28 |
2019-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223374
|
7.5 |
HIGH
Network
|
teamspeak
|
teamspeak
|
The TeamSpeak client before 3.3.2 allows remote servers to trigger a crash via the 0xe2 0x81 0xa8 0xe2 0x81 0xa7 byte sequence, aka Unicode characters U+2068 (FIRST STRONG ISOLATE) and U+2067 (RIGHT-…
|
NVD-CWE-noinfo
|
CVE-2019-15502
|
2024-11-21 13:28 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223375
|
8.8 |
HIGH
Network
|
manageyourteam
|
myt_project_management
|
MyT Project Management 1.5.1 lacks CSRF protection and, for example, allows a user/create CSRF attack. This could lead to an attacker tricking the administrator into executing arbitrary code via a sp…
|
CWE-352
Origin Validation Error
|
CVE-2019-15496
|
2024-11-21 13:28 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223376
|
5.4 |
MEDIUM
Network
|
librenms
|
librenms
|
LibreNMS v1.54 has XSS in the Create User, Inventory, Add Device, Notifications, Alert Rule, Create Maintenance, and Alert Template sections of the admin console. This could lead to cookie stealing a…
|
CWE-79
Cross-site Scripting
|
CVE-2019-15230
|
2024-11-21 13:28 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223377
|
9.8 |
CRITICAL
Network
|
gallagher
|
command_centre
|
An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2). Upon an upgrade, if a custom service account is in use and the visitor management service is installed, the Windows use…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-15294
|
2024-11-21 13:28 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223378
|
9.8 |
CRITICAL
Network
|
blackbox onelan
|
icompel_firmware net-top-box_firmware
|
Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow remote attackers to access devices remotely via SSH, …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-15497
|
2024-11-21 13:28 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223379
|
9.8 |
CRITICAL
Network
|
ncurses_project
|
ncurses
|
An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are instr and mvwinstr buffer overflows because interaction with C functions is mishandled.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-15548
|
2024-11-21 13:28 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223380
|
7.5 |
HIGH
Network
|
ncurses_project
|
ncurses
|
An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are format string issues in printw functions because C format arguments are mishandled.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2019-15547
|
2024-11-21 13:28 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|