|
211691
|
7.5 |
HIGH
Network
|
dlink
|
dir-825_rev.b_firmware
|
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. There is an information disclosure vulnerability via requests for the router_info.xml document. This will reveal the PIN code, MAC addres…
|
CWE-200
Information Exposure
|
CVE-2019-9126
|
2024-11-21 13:51 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211692
|
9.8 |
CRITICAL
Network
|
d-link
|
dir-878_firmware
|
An issue was discovered on D-Link DIR-878 1.12B01 devices. Because strncpy is misused, there is a stack-based buffer overflow vulnerability that does not require authentication via the HNAP_AUTH HTTP…
|
CWE-787 CWE-306
Out-of-bounds Write Missing Authentication for Critical Function
|
CVE-2019-9125
|
2024-11-21 13:51 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211693
|
9.8 |
CRITICAL
Network
|
d-link
|
dir-878_firmware
|
An issue was discovered on D-Link DIR-878 1.12B01 devices. At the /HNAP1 URI, an attacker can log in with a blank password.
|
CWE-287
Improper Authentication
|
CVE-2019-9124
|
2024-11-21 13:51 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211694
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-825_rev.b_firmware
|
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. The "user" account has a blank password.
|
CWE-521
Weak Password Requirements
|
CVE-2019-9123
|
2024-11-21 13:51 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211695
|
7.8 |
HIGH
Local
|
sublimetext
|
sublime_text_3
|
DLL hijacking is possible in Sublime Text 3 version 3.1.1 build 3176 on 32-bit Windows platforms because a Trojan horse api-ms-win-core-fibers-l1-1-1.dll or api-ms-win-core-localization-l1-2-1.dll fi…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-9116
|
2024-11-21 13:51 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211696
|
8.8 |
HIGH
Network
|
dlink
|
dir-825_rev.b_firmware
|
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the ntp_server parameter in an ntp_sync.cgi POST request.
|
NVD-CWE-noinfo
|
CVE-2019-9122
|
2024-11-21 13:51 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211697
|
9.8 |
CRITICAL
Network
|
irisnet
|
irisnet-crypto
|
In irisnet-crypto before 1.1.7 for IRISnet, the util/utils.js file allows code execution because of unsafe eval usage.
|
CWE-94
Code Injection
|
CVE-2019-9115
|
2024-11-21 13:51 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211698
|
8.8 |
HIGH
Network
|
libming
|
ming
|
Ming (aka libming) 0.4.8 has an out of bounds write vulnerability in the function strcpyext() in the decompile.c file in libutil.a.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9114
|
2024-11-21 13:51 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211699
|
8.8 |
HIGH
Network
|
libming
|
ming
|
Ming (aka libming) 0.4.8 has a NULL pointer dereference in the function getString() in the decompile.c file in libutil.a.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-9113
|
2024-11-21 13:51 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211700
|
5.5 |
MEDIUM
Local
|
micode
|
xiaomi_perseus-p-oss
|
The msm gpu driver for custom Linux kernels on the Xiaomi perseus-p-oss MIX 3 device through 2018-11-26 has an integer overflow and OOPS because of missing checks of the count argument in _sde_debugf…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-9112
|
2024-11-21 13:51 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|