|
222221
|
7.5 |
HIGH
Network
|
agendaless oracle debian fedoraproject redhat
|
waitress communications_cloud_native_core_network_function_cloud_native_environment debian_linux fedora openstack
|
Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for the start-line and header fields is the sequence CRLF, a recipient MAY recognize…
|
CWE-444
HTTP Request Smuggling
|
CVE-2019-16785
|
2024-11-21 13:31 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222222
|
9.8 |
CRITICAL
Network
|
beckhoff
|
twincat
|
Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remote Code Execution (as SYSTEM) via the Beckhoff ADS protocol.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2019-16871
|
2024-11-21 13:31 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222223
|
5.9 |
MEDIUM
Network
|
rack_project fedoraproject opensuse
|
rack fedora leap
|
There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched in versions 1.6.12 and 2.0.8. Attackers may be able to find and hijack session…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-16782
|
2024-11-21 13:31 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222224
|
9.8 |
CRITICAL
Network
|
google
|
tensorflow
|
In TensorFlow before 1.15, a heap buffer overflow in UnsortedSegmentSum can be produced when the Index template argument is int32. In this case data_size and num_segments fields are truncated from in…
|
CWE-681
Incorrect Conversion between Numeric Types
|
CVE-2019-16778
|
2024-11-21 13:31 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222225
|
5.9 |
MEDIUM
Network
|
excon_project opensuse debian
|
excon leap backports_sle debian_linux
|
In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent req…
|
CWE-362
Race Condition
|
CVE-2019-16779
|
2024-11-21 13:31 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222226
|
9.8 |
CRITICAL
Network
|
skymee petwant
|
petalk_ai_firmware pf-103_firmware
|
The processCommandSetMac() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.
|
CWE-78
OS Command
|
CVE-2019-16737
|
2024-11-21 13:31 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222227
|
9.8 |
CRITICAL
Network
|
skymee petwant
|
petalk_ai_firmware pf-103_firmware
|
A stack-based buffer overflow in processCommandUploadSnapshot in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to cause denial of service or run arb…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-16736
|
2024-11-21 13:31 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222228
|
9.8 |
CRITICAL
Network
|
skymee petwant
|
petalk_ai_firmware pf-103_firmware
|
A stack-based buffer overflow in processCommandUploadLog in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to cause denial of service or run arbitrar…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-16735
|
2024-11-21 13:31 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222229
|
9.8 |
CRITICAL
Network
|
skymee petwant
|
petalk_ai_firmware pf-103_firmware
|
Use of default credentials for the TELNET server in Petwant PF-103 firmware 4.3.2.50 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-16734
|
2024-11-21 13:31 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222230
|
9.8 |
CRITICAL
Network
|
skymee petwant
|
petalk_ai_firmware pf-103_firmware
|
processCommandSetUid() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.
|
CWE-78
OS Command
|
CVE-2019-16733
|
2024-11-21 13:31 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|