|
219151
|
5.3 |
MEDIUM
Network
|
serve-here.js_project
|
serve-here.js
|
Path traversal vulnerability in version up to v1.1.3 in serve-here.js npm module allows attackers to list any file in arbitrary folder.
|
CWE-22
Path Traversal
|
CVE-2019-5444
|
2024-11-21 13:44 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219152
|
6.5 |
MEDIUM
Adjacent
|
huawei
|
mate_20_x_firmware
|
There is a path traversal vulnerability on Huawei Share. The software does not properly validate the path, an attacker could crafted a file path when transporting file through Huawei Share, successfu…
|
CWE-22
Path Traversal
|
CVE-2019-5221
|
2024-11-21 13:44 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219153
|
4.6 |
MEDIUM
Physics
|
huawei
|
mate_20_x_firmware mate_20_firmware honor_magic_2_firmware
|
There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently verify the permission, an attacker could do a certain operation on certain step…
|
CWE-863
Incorrect Authorization
|
CVE-2019-5220
|
2024-11-21 13:44 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219154
|
8.8 |
HIGH
Network
|
libsdl debian opensuse canonical
|
sdl2_image debian_linux leap backports_sle ubuntu_linux
|
An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted file can cause an integer overflow, resulting in too little memory being allocate…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-5052
|
2024-11-21 13:44 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219155
|
8.8 |
HIGH
Network
|
libsdl debian opensuse canonical
|
sdl2_image debian_linux leap backports_sle ubuntu_linux
|
An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error handler can lead to a buffer overflow and potential code execution…
|
CWE-787 CWE-755
Out-of-bounds Write Improper Handling of Exceptional Conditions
|
CVE-2019-5051
|
2024-11-21 13:44 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219156
|
7.8 |
HIGH
Local
|
haxx oracle netapp
|
curl http_server enterprise_manager_ops_center oss_support_tools mysql_server snapcenter oncommand_unified_manager oncommand_workflow_automation oncommand_insight
|
A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") …
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-5443
|
2024-11-21 13:44 |
2019-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219157
|
5.3 |
MEDIUM
Network
|
netgear kcodes
|
r8000_firmware netusb.ko
|
An exploitable information disclosure vulnerability exists in the KCodes NetUSB.ko kernel module that enables the ReadySHARE Printer functionality of at least two NETGEAR Nighthawk Routers and potent…
|
CWE-200
Information Exposure
|
CVE-2019-5017
|
2024-11-21 13:44 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219158
|
9.1 |
CRITICAL
Network
|
netgear kcodes
|
r8000_firmware r7900_firmware netusb.ko
|
An exploitable arbitrary memory read vulnerability exists in the KCodes NetUSB.ko kernel module which enables the ReadySHARE Printer functionality of at least two NETGEAR Nighthawk Routers and potent…
|
CWE-200
Information Exposure
|
CVE-2019-5016
|
2024-11-21 13:44 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219159
|
6.5 |
MEDIUM
Network
|
videolan
|
vlc_media_player
|
A Buffer Overflow in VLC Media Player < 3.0.7 causes a crash which can possibly be further developed into a remote code execution exploit.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-5439
|
2024-11-21 13:44 |
2019-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219160
|
6.1 |
MEDIUM
Network
|
huawei
|
hedex_lite
|
There is a reflection XSS vulnerability in the HedEx products. Remote attackers send malicious links to users and trick users to click. Successfully exploit cloud allow the attacker to initiate XSS a…
|
CWE-79
Cross-site Scripting
|
CVE-2019-5286
|
2024-11-21 13:44 |
2019-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|