|
223121
|
4.9 |
MEDIUM
Network
|
silver-peak
|
unity_edgeconnect_sd-wan_firmware
|
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows ..%2f directory traversal via a rest/json/configdb/download/ URI.
|
CWE-22
Path Traversal
|
CVE-2019-16105
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223122
|
6.1 |
MEDIUM
Network
|
silver-peak
|
unity_edgeconnect_sd-wan_firmware
|
Silver Peak EdgeConnect SD-WAN before 8.1.7.x has reflected XSS via the rest/json/configdb/download/ PATH_INFO.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16104
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223123
|
7.2 |
HIGH
Network
|
silver-peak
|
unity_edgeconnect_sd-wan_firmware
|
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows privilege escalation (by administrators) from the menu to a root Bash OS shell via the spsshell feature.
|
NVD-CWE-noinfo
|
CVE-2019-16103
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223124
|
9.8 |
CRITICAL
Network
|
silver-peak
|
unity_edgeconnect_sd-wan_firmware
|
Silver Peak EdgeConnect SD-WAN before 8.1.7.x has an SNMP service with a public value for rocommunity and trapcommunity.
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2019-16102
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223125
|
5.3 |
MEDIUM
Network
|
silver-peak
|
unity_edgeconnect_sd-wan_firmware
|
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to obtain potentially sensitive stack traces by sending incorrect JSON data to the REST API, such as the rest/json/banners URI.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2019-16101
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223126
|
7.5 |
HIGH
Network
|
silver-peak
|
unity_edgeconnect_sd-wan_firmware
|
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to trigger a web-interface outage via slow client-side HTTP traffic from a single source.
|
NVD-CWE-noinfo
|
CVE-2019-16100
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223127
|
8.8 |
HIGH
Network
|
silver-peak
|
unity_edgeconnect_sd-wan_firmware
|
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows CSRF via JSON data to a .swf file.
|
CWE-352
Origin Validation Error
|
CVE-2019-16099
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223128
|
6.5 |
MEDIUM
Network
|
linuxfoundation
|
harbor
|
core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do…
|
CWE-862
Missing Authorization
|
CVE-2019-16097
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223129
|
7.5 |
HIGH
Network
|
kilo_project
|
kilo
|
Kilo 0.0.1 has a heap-based buffer overflow because there is an integer overflow in a calculation involving the number of tabs in one row.
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2019-16096
|
2024-11-21 13:30 |
2019-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223130
|
7.5 |
HIGH
Network
|
symonics canonical
|
libmysofa ubuntu_linux
|
Symonics libmysofa 0.7 has an invalid read in getDimension in hrtf/reader.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-16095
|
2024-11-21 13:30 |
2019-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|