|
222911
|
7.5 |
HIGH
Network
|
matrixssl
|
matrixssl
|
In MatrixSSL before 4.2.2 Open, the DTLS server can encounter an invalid pointer free (leading to memory corruption and a daemon crash) via a crafted incoming network message, a different vulnerabili…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-16747
|
2024-11-21 13:31 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222912
|
6.5 |
MEDIUM
Network
|
solarwinds
|
webhelpdesk
|
SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2019-16959
|
2024-11-21 13:31 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222913
|
5.4 |
MEDIUM
Network
|
solarwinds
|
webhelpdesk
|
SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16957
|
2024-11-21 13:31 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222914
|
5.4 |
MEDIUM
Network
|
solarwinds
|
webhelpdesk
|
SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16955
|
2024-11-21 13:31 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222915
|
5.4 |
MEDIUM
Network
|
solarwinds
|
help_desk
|
Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16958
|
2024-11-21 13:31 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222916
|
7.5 |
HIGH
Network
|
mozilla siemens
|
network_security_services ruggedcom_rox_mx5000_firmware ruggedcom_rox_rx1400_firmware ruggedcom_rox_rx1500_firmware ruggedcom_rox_rx1501_firmware ruggedcom_rox_rx1510_firmware rugge…
|
In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
|
CWE-295
Improper Certificate Validation
|
CVE-2019-17007
|
2024-11-21 13:31 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222917
|
9.8 |
CRITICAL
Network
|
siemens mozilla netapp
|
ruggedcom_rox_mx5000_firmware ruggedcom_rox_rx1400_firmware ruggedcom_rox_rx1500_firmware ruggedcom_rox_rx1501_firmware ruggedcom_rox_rx1510_firmware ruggedcom_rox_rx1511_firmware r…
|
In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the in…
|
CWE-119 CWE-20
Incorrect Access of Indexable Resource ('Range Error') Improper Input Validation
|
CVE-2019-17006
|
2024-11-21 13:31 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222918
|
6.5 |
MEDIUM
Adjacent
|
august
|
august_home connect_wi-fi_bridge_firmware
|
Use of hard-coded cryptographic key vulnerability in August Connect Wi-Fi Bridge App, Connect Firmware allows an attacker to decrypt an intercepted payload containing the Wi-Fi network authentication…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-17098
|
2024-11-21 13:31 |
2020-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222919
|
7.8 |
HIGH
Local
|
ivanti
|
workspace_control
|
In Ivanti WorkSpace Control before 10.4.40.0, a user can elevate rights on the system by hijacking certain user registries. This is possible because pwrgrid.exe first checks the Current User registry…
|
CWE-269
Improper Privilege Management
|
CVE-2019-17066
|
2024-11-21 13:31 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222920
|
6.7 |
MEDIUM
Local
|
netatmo
|
smart_indoor_camera_firmware
|
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in firmware versions prior to x.xx of Netatmo Smart Indoor Camera allows an attacker to execute comma…
|
CWE-77
Command Injection
|
CVE-2019-17101
|
2024-11-21 13:31 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|