|
223171
|
2.7 |
LOW
Network
|
killernetworking
|
killer_control_center
|
An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120404 in KfeCo10X64.sys fails to validate an offset passed as a parameter during a memory operation, leading to an out…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15664
|
2024-11-21 13:29 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223172
|
2.7 |
LOW
Network
|
killernetworking
|
killer_control_center
|
An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120404 in KfeCo10X64.sys fails to validate an offset passed as a parameter during a memory operation, leading to an out…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15663
|
2024-11-21 13:29 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223173
|
2.7 |
LOW
Network
|
killernetworking
|
killer_control_center
|
An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120444 in KfeCo10X64.sys fails to validate an offset passed as a parameter during a memory operation, leading to an arb…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15662
|
2024-11-21 13:29 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223174
|
7.2 |
HIGH
Network
|
killernetworking
|
killer_control_center
|
An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120004 in KfeCo10X64.sys fails to validate parameters, leading to a stack-based buffer overflow, which can lead to code…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-15661
|
2024-11-21 13:29 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223175
|
6.1 |
MEDIUM
Network
|
netsas
|
enigma_network_management_solution
|
A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that could allow a threat actor to inject malicious code directly into the applicat…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16069
|
2024-11-21 13:29 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223176
|
8.8 |
HIGH
Network
|
netsas
|
enigma_network_management_solution
|
A CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to trick a victim into submitting a malicious manage_files.cgi request. This can be t…
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2019-16068
|
2024-11-21 13:29 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223177
|
7.5 |
HIGH
Network
|
netsas
|
enigma_network_management_solution
|
NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data rendered within web pages. It is possible for an attacker to expose unencrypted sensitive data.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-16063
|
2024-11-21 13:29 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223178
|
6.1 |
MEDIUM
Network
|
netsas
|
enigma_network_management_solution
|
A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that could allow a threat actor to inject malicious code directly into the applicat…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16070
|
2024-11-21 13:29 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223179
|
7.5 |
HIGH
Network
|
netsas
|
enigma_network_management_solution
|
NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web application. The use of weak authentication transmitted over cleartext protocols can…
|
CWE-319 CWE-522
Cleartext Transmission of Sensitive Information Insufficiently Protected Credentials
|
CVE-2019-16067
|
2024-11-21 13:29 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223180
|
8.8 |
HIGH
Network
|
netsas
|
enigma_network_management_solution
|
An unrestricted file upload vulnerability exists in user and system file upload functions in NETSAS Enigma NMS 65.0.0 and prior. This allows an attacker to upload malicious files and perform arbitrar…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-16066
|
2024-11-21 13:29 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|