|
223361
|
6.1 |
MEDIUM
Network
|
fortinet
|
fortiauthenticator
|
An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cross-site scripting attack (XSS) via a parameter of t…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16154
|
2024-11-21 13:30 |
2020-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223362
|
5.3 |
MEDIUM
Network
|
dten
|
d5_firmware d7_firmware
|
DTEN D5 and D7 before 1.3.2 devices allows remote attackers to read saved whiteboard image PDF documents via storage/emulated/0/Notes/PDF on TCP port 8080 without authentication.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-16271
|
2024-11-21 13:30 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223363
|
7.5 |
HIGH
Network
|
dten
|
d5_firmware d7_firmware
|
DTEN D5 before 1.3 and D7 before 1.3 devices transfer customer data files via unencrypted HTTP.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-16274
|
2024-11-21 13:30 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223364
|
9.8 |
CRITICAL
Network
|
dten
|
d5_firmware d7_firmware
|
DTEN D5 and D7 before 1.3.4 devices allow unauthenticated root shell access through Android Debug Bridge (adb), leading to arbitrary code execution and system administration. Also, this provides a co…
|
NVD-CWE-noinfo
|
CVE-2019-16273
|
2024-11-21 13:30 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223365
|
9.8 |
CRITICAL
Network
|
dten
|
d5_firmware d7_firmware
|
On DTEN D5 and D7 before 1.3.4 devices, factory settings allows for firmware reflash and Android Debug Bridge (adb) enablement.
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2019-16272
|
2024-11-21 13:30 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223366
|
9.8 |
CRITICAL
Network
|
yandex
|
clickhouse
|
In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve RCE or DoS via native protocol.
|
CWE-125 CWE-787 CWE-191
Out-of-bounds Read Out-of-bounds Write Integer Underflow (Wrap or Wraparound)
|
CVE-2019-16535
|
2024-11-21 13:30 |
2019-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223367
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-601_firmware
|
D-Link DIR-601 B1 2.00NA devices are vulnerable to authentication bypass. They do not check for authentication at the server side and rely on client-side validation, which is bypassable. NOTE: this i…
|
CWE-287
Improper Authentication
|
CVE-2019-16327
|
2024-11-21 13:30 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223368
|
8.8 |
HIGH
Network
|
dlink
|
dir-601_firmware
|
D-Link DIR-601 B1 2.00NA devices have CSRF because no anti-CSRF token is implemented. A remote attacker could exploit this in conjunction with CVE-2019-16327 to enable remote router management and de…
|
CWE-352
Origin Validation Error
|
CVE-2019-16326
|
2024-11-21 13:30 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223369
|
7.5 |
HIGH
Network
|
adobe
|
acrobat_dc acrobat_reader_dc
|
Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an out-…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-16465
|
2024-11-21 13:30 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223370
|
9.8 |
CRITICAL
Network
|
adobe
|
acrobat_dc acrobat_reader_dc
|
Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an use …
|
CWE-416
Use After Free
|
CVE-2019-16464
|
2024-11-21 13:30 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|