|
219641
|
2.4 |
LOW
Physics
|
google
|
android
|
An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can view home-screen wallpaper by adjusting the brightness of a locked screen. The Samsung ID is SVE-2019-15540 (Dece…
|
NVD-CWE-noinfo
|
CVE-2019-20534
|
2024-11-21 13:38 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219642
|
3.3 |
LOW
Local
|
google
|
android
|
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (released in China or India) software. The S Secure app can launch masked apps without a password. The Samsung ID is …
|
CWE-287
Improper Authentication
|
CVE-2019-20533
|
2024-11-21 13:38 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219643
|
5.3 |
MEDIUM
Network
|
google
|
android
|
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can access the Developer options without authentication. The Samsung ID is SVE-2019-15800 (Decem…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-20532
|
2024-11-21 13:38 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219644
|
7.1 |
HIGH
Local
|
google
|
android
|
An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software. The Wi-Fi kernel drivers have an out-of-bounds Read. The Samsung IDs are SVE-2019-15692, SVE-2019-15693 (Dece…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-20531
|
2024-11-21 13:38 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219645
|
9.8 |
CRITICAL
Network
|
google
|
android
|
An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), P(9.0), and Q(10.0) software. Arbitrary code execution is possible on the lock screen. The Samsung ID is SVE-2019-15266 (Decembe…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-20530
|
2024-11-21 13:38 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219646
|
9.8 |
CRITICAL
Network
|
rbsoft
|
autoupdater.net
|
AutoUpdater.cs in AutoUpdater.NET before 1.5.8 allows XXE.
|
CWE-611
XXE
|
CVE-2019-20627
|
2024-11-21 13:38 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219647
|
6.5 |
MEDIUM
Adjacent
|
honda
|
hr-v_2017_firmware
|
The remote keyless system on Honda HR-V 2017 vehicles sends the same RF signal for each door-open request, which might allow a replay attack.
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2019-20626
|
2024-11-21 13:38 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219648
|
6.1 |
MEDIUM
Network
|
igniterealtime
|
openfire
|
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20526
|
2024-11-21 13:38 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219649
|
6.1 |
MEDIUM
Network
|
igniterealtime
|
openfire
|
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20525
|
2024-11-21 13:38 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219650
|
6.1 |
MEDIUM
Network
|
frappe
|
erpnext
|
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20521
|
2024-11-21 13:38 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|