|
223451
|
7.5 |
HIGH
Network
|
gnu
|
serveez
|
GNU Serveez through 0.2.2 has an Information Leak. An attacker may send an HTTP POST request to the /cgi-bin/reader URI. The attacker must include a Content-length header with a large positive value …
|
CWE-681
Incorrect Conversion between Numeric Types
|
CVE-2019-16200
|
2024-11-21 13:30 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223452
|
8.1 |
HIGH
Network
|
blade-group
|
shadow
|
The network protocol of Blade Shadow though 2.13.3 allows remote attackers to take control of a Shadow instance and execute arbitrary code by only knowing the victim's IP address, because packet data…
|
NVD-CWE-noinfo
|
CVE-2019-16110
|
2024-11-21 13:30 |
2019-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223453
|
5.5 |
MEDIUM
Local
|
broadcom
|
brocade_sannav
|
Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save.
|
CWE-532 CWE-311
Inclusion of Sensitive Information in Log Files Missing Encryption of Sensitive Data
|
CVE-2019-16210
|
2024-11-21 13:30 |
2019-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223454
|
7.4 |
HIGH
Network
|
broadcom
|
brocade_sannav
|
A vulnerability, in The ReportsTrustManager class of Brocade SANnav versions before v2.0, could allow an attacker to perform a man-in-the-middle attack against Secure Sockets Layer(SSL)connections.
|
CWE-295
Improper Certificate Validation
|
CVE-2019-16209
|
2024-11-21 13:30 |
2019-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223455
|
7.5 |
HIGH
Network
|
broadcom
|
brocade_sannav
|
Password-based encryption (PBE) algorithm, of Brocade SANnav versions before v2.0, has a weakness in generating cryptographic keys that may allow an attacker to decrypt passwords used with several se…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-16208
|
2024-11-21 13:30 |
2019-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223456
|
7.8 |
HIGH
Local
|
broadcom
|
brocade_sannav
|
Brocade SANnav versions before v2.0 use a hard-coded password, which could allow local authenticated attackers to access a back-end database and gain privileges.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-16207
|
2024-11-21 13:30 |
2019-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223457
|
5.5 |
MEDIUM
Local
|
broadcom
|
brocade_sannav
|
The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ and the 'debug' logging level; which could allow a local authenticated attacker…
|
CWE-532 CWE-311
Inclusion of Sensitive Information in Log Files Missing Encryption of Sensitive Data
|
CVE-2019-16206
|
2024-11-21 13:30 |
2019-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223458
|
8.8 |
HIGH
Network
|
broadcom
|
brocade_sannav
|
A vulnerability, in Brocade SANnav versions before v2.0, could allow remote attackers to brute-force a valid session ID. The vulnerability is due to an insufficiently random session ID for several po…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2019-16205
|
2024-11-21 13:30 |
2019-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223459
|
6.5 |
MEDIUM
Adjacent
|
samsung
|
galaxy_s8_plus_firmware galaxy_s3_firmware galaxy_note_2_firmware
|
Samsung Galaxy S8 plus (Android version: 8.0.0, Build Number: R16NW.G955USQU5CRG3, Baseband Vendor: Qualcomm Snapdragon 835, Baseband: G955USQU5CRG3), Samsung Galaxy S3 (Android version: 4.3, Build N…
|
NVD-CWE-noinfo
|
CVE-2019-16401
|
2024-11-21 13:30 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223460
|
6.5 |
MEDIUM
Adjacent
|
samsung
|
galaxy_s8_plus_firmware galaxy_s3_firmware galaxy_note_2_firmware
|
Samsung Galaxy S8 plus (Android version: 8.0.0, Build Number: R16NW.G955USQU5CRG3, Baseband Vendor: Qualcomm Snapdragon 835, Baseband: G955USQU5CRG3), Samsung Galaxy S3 (Android version: 4.3, Build N…
|
NVD-CWE-noinfo
|
CVE-2019-16400
|
2024-11-21 13:30 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|