|
211861
|
9.8 |
CRITICAL
Network
|
d-link
|
dir-878_firmware
|
An issue was discovered on D-Link DIR-878 1.12B01 devices. At the /HNAP1 URI, an attacker can log in with a blank password.
|
CWE-287
Improper Authentication
|
CVE-2019-9124
|
2024-11-21 13:51 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211862
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-825_rev.b_firmware
|
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. The "user" account has a blank password.
|
CWE-521
Weak Password Requirements
|
CVE-2019-9123
|
2024-11-21 13:51 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211863
|
7.8 |
HIGH
Local
|
sublimetext
|
sublime_text_3
|
DLL hijacking is possible in Sublime Text 3 version 3.1.1 build 3176 on 32-bit Windows platforms because a Trojan horse api-ms-win-core-fibers-l1-1-1.dll or api-ms-win-core-localization-l1-2-1.dll fi…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-9116
|
2024-11-21 13:51 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211864
|
8.8 |
HIGH
Network
|
dlink
|
dir-825_rev.b_firmware
|
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the ntp_server parameter in an ntp_sync.cgi POST request.
|
NVD-CWE-noinfo
|
CVE-2019-9122
|
2024-11-21 13:51 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211865
|
9.8 |
CRITICAL
Network
|
irisnet
|
irisnet-crypto
|
In irisnet-crypto before 1.1.7 for IRISnet, the util/utils.js file allows code execution because of unsafe eval usage.
|
CWE-94
Code Injection
|
CVE-2019-9115
|
2024-11-21 13:51 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211866
|
8.8 |
HIGH
Network
|
libming
|
ming
|
Ming (aka libming) 0.4.8 has an out of bounds write vulnerability in the function strcpyext() in the decompile.c file in libutil.a.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9114
|
2024-11-21 13:51 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211867
|
8.8 |
HIGH
Network
|
libming
|
ming
|
Ming (aka libming) 0.4.8 has a NULL pointer dereference in the function getString() in the decompile.c file in libutil.a.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-9113
|
2024-11-21 13:51 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211868
|
5.5 |
MEDIUM
Local
|
micode
|
xiaomi_perseus-p-oss
|
The msm gpu driver for custom Linux kernels on the Xiaomi perseus-p-oss MIX 3 device through 2018-11-26 has an integer overflow and OOPS because of missing checks of the count argument in _sde_debugf…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-9112
|
2024-11-21 13:51 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211869
|
5.5 |
MEDIUM
Local
|
micode
|
xiaomi_perseus-p-oss
|
The msm gpu driver for custom Linux kernels on the Xiaomi perseus-p-oss MIX 3 device through 2018-11-26 has an integer overflow and OOPS because of missing checks of the count argument in sde_evtlog_…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-9111
|
2024-11-21 13:51 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211870
|
6.1 |
MEDIUM
Network
|
wuzhicms
|
wuzhi_cms
|
XSS exists in WUZHI CMS 4.1.0 via index.php?m=content&f=postinfo&v=listing&set_iframe=[XSS] to coreframe/app/content/postinfo.php.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9110
|
2024-11-21 13:51 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|