|
219051
|
6.8 |
MEDIUM
Adjacent
|
huawei
|
p30_pro_firmware p30_firmware
|
There is a man-in-the-middle (MITM) vulnerability on Huawei P30 smartphones versions before ELE-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1), and P30 Pro versions before VOG-AL00 9.1.0.162 (C01E160R1P12/…
|
NVD-CWE-noinfo
|
CVE-2019-5215
|
2024-11-21 13:44 |
2019-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219052
|
3.9 |
LOW
Physics
|
huawei
|
mate20_firmware
|
Mate20 Huawei smartphones versions earlier than HMA-AL00C00B175 have an out-of-bounds read vulnerability. An attacker with a high permission runs some specific commands on the smartphone. Due to insu…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-5296
|
2024-11-21 13:44 |
2019-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219053
|
4.6 |
MEDIUM
Physics
|
huawei
|
y9_2019_firmware
|
There is an information leak vulnerability in some Huawei phones, versions earlier than Jackman-L21 8.2.0.155(C185R1P2). When a local attacker uses the camera of a smartphone, the attacker can exploi…
|
NVD-CWE-noinfo
|
CVE-2019-5281
|
2024-11-21 13:44 |
2019-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219054
|
5.5 |
MEDIUM
Local
|
huawei
|
mate_9_pro_fimware
|
Mate 9 Pro Huawei smartphones earlier than LON-L29C 8.0.0.361(C636) versions have an information leak vulnerability due to the lack of input validation. An attacker tricks the user who has root privi…
|
CWE-20
Improper Input Validation
|
CVE-2019-5244
|
2024-11-21 13:44 |
2019-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219055
|
8.1 |
HIGH
Network
|
revive-adserver
|
revive_adserver
|
Use of cryptographically weak PRNG in the password recovery token generation of Revive Adserver < v4.2.1 causes a potential authentication bypass attack if an attacker exploits the password recovery …
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2019-5440
|
2024-11-21 13:44 |
2019-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219056
|
7.8 |
HIGH
Local
|
haxx opensuse fedoraproject debian f5 netapp oracle
|
libcurl leap fedora debian_linux traffix_signaling_delivery_controller steelstore_cloud_integrated_storage solidfire hci_management_node enterprise_manager_ops_center mysql…
|
A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-5436
|
2024-11-21 13:44 |
2019-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219057
|
3.7 |
LOW
Network
|
haxx
|
curl
|
An integer overflow in curl's URL API results in a buffer overflow in libcurl 7.62.0 to and including 7.64.1.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-5435
|
2024-11-21 13:44 |
2019-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219058
|
5.3 |
MEDIUM
Network
|
harpjs
|
harp
|
Path traversal using symlink in npm harp module versions <= 0.29.0.
|
CWE-59
Link Following
|
CVE-2019-5438
|
2024-11-21 13:44 |
2019-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219059
|
5.3 |
MEDIUM
Network
|
harpjs
|
harp
|
Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp server rules.Vulnerable versions are <= 0.29.0 and…
|
CWE-200
Information Exposure
|
CVE-2019-5437
|
2024-11-21 13:44 |
2019-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219060
|
8.1 |
HIGH
Network
|
sqlite canonical
|
sqlite ubuntu_linux
|
An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause a use after free vulnerability, potentially result…
|
CWE-416
Use After Free
|
CVE-2019-5018
|
2024-11-21 13:44 |
2019-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|