|
219781
|
8.8 |
HIGH
Network
|
crestron
|
am-100_firmware am-101_firmware
|
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to argumention injection to the curl binary via crafted HTTP requests to return.cgi. A remote, authenticated atta…
|
CWE-88
Argument Injection
|
CVE-2019-3931
|
2024-11-21 13:42 |
2019-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219782
|
5.3 |
MEDIUM
Network
|
crestron
|
am-100_firmware am-101_firmware
|
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allow any user to obtain the presentation passcode via the iso.3.6.1.4.1.3212.100.3.2.7.4 OIDs. A remote, unauthenticated attack…
|
NVD-CWE-Other
|
CVE-2019-3928
|
2024-11-21 13:42 |
2019-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219783
|
9.8 |
CRITICAL
Network
|
crestron
|
am-100_firmware am-101_firmware
|
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 anyone can change the administrator and moderator passwords via the iso.3.6.1.4.1.3212.100.3.2.8.1 and iso.3.6.1.4.1.3212.100.3.…
|
CWE-287
Improper Authentication
|
CVE-2019-3927
|
2024-11-21 13:42 |
2019-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219784
|
9.8 |
CRITICAL
Network
|
crestron
|
am-100_firmware am-101_firmware
|
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.14.1. A remote, unauthenticated attacker can use thi…
|
CWE-78
OS Command
|
CVE-2019-3926
|
2024-11-21 13:42 |
2019-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219785
|
9.8 |
CRITICAL
Network
|
crestron
|
am-100_firmware am-101_firmware
|
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.9.3. A remote, unauthenticated attacker can use this…
|
CWE-78
OS Command
|
CVE-2019-3925
|
2024-11-21 13:42 |
2019-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219786
|
9.8 |
CRITICAL
Network
|
crestron barco extron teqavit sharp optoma blackbox infocus
|
am-100_firmware am-101_firmware wepresent_wipg-1000p_firmware wepresent_wipg-1600w_firmware sharelink_200_firmware sharelink_250_firmware wips710_firmware pn-l703wa_firmware w…
|
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 fir…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-3930
|
2024-11-21 13:42 |
2019-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219787
|
9.8 |
CRITICAL
Network
|
crestron barco extron teqavit sharp optoma blackbox infocus
|
am-100_firmware am-101_firmware wepresent_wipg-1000p_firmware wepresent_wipg-1600w_firmware sharelink_200_firmware sharelink_250_firmware wips710_firmware pn-l703wa_firmware w…
|
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 fir…
|
CWE-78
OS Command
|
CVE-2019-3929
|
2024-11-21 13:42 |
2019-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219788
|
7.5 |
HIGH
Network
|
atlassian
|
jira jira_server
|
The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to see information for archived projects through a missing authoris…
|
CWE-862
Missing Authorization
|
CVE-2019-3399
|
2024-11-21 13:42 |
2019-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219789
|
9.8 |
CRITICAL
Network
|
facebook
|
wangle
|
Wangle's LineBasedFrameDecoder contains logic for identifying newlines which incorrectly advances a buffer, leading to a potential underflow. This affects versions of Wangle prior to v2019.04.22.00
|
CWE-787
Out-of-bounds Write
|
CVE-2019-3563
|
2024-11-21 13:42 |
2019-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219790
|
6.1 |
MEDIUM
Network
|
oculus
|
oculus_browser
|
A remote web page could inject arbitrary HTML code into the Oculus Browser UI, allowing an attacker to spoof UI and potentially execute code. This affects the Oculus Browser starting from version 5.2…
|
CWE-79
Cross-site Scripting
|
CVE-2019-3562
|
2024-11-21 13:42 |
2019-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|