|
211691
|
7.5 |
HIGH
Network
|
apple apache canonical debian fedoraproject synology opensuse redhat oracle mcafee f5 nodejs
|
swiftnio traffic_server ubuntu_linux debian_linux fedora skynas diskstation_manager vs960hd_firmware leap software_collections jboss_core_services enterprise_linux
|
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the st…
|
NVD-CWE-Other
|
CVE-2019-9513
|
2024-11-21 13:51 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211692
|
7.5 |
HIGH
Network
|
apple apache canonical debian synology fedoraproject opensuse redhat oracle mcafee f5 nodejs
|
swiftnio traffic_server ubuntu_linux debian_linux skynas diskstation_manager vs960hd_firmware fedora leap software_collections jboss_core_services enterprise_linux
|
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-9511
|
2024-11-21 13:51 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211693
|
9.8 |
CRITICAL
Network
|
imgtech
|
zoneplayer
|
ZInsVX.dll ActiveX Control 2018.02 and earlier in Zoneplayer contains a vulnerability that could allow remote attackers to execute arbitrary files by setting the arguments to the ActiveX method. This…
|
NVD-CWE-noinfo
|
CVE-2019-9141
|
2024-11-21 13:51 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211694
|
8.1 |
HIGH
Network
|
happypointcard
|
happypoint
|
When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesn't check Deeplink URL correctly. This could lead to javascript code execution, url redirection, sensitive infor…
|
CWE-601
Open Redirect
|
CVE-2019-9140
|
2024-11-21 13:51 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211695
|
7.8 |
HIGH
Local
|
trendmicro
|
officescan
|
A DLL side-loading vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow an authenticated attacker to gain code execution and terminate the product's process - disabling endpoint protec…
|
CWE-426
Untrusted Search Path
|
CVE-2019-9492
|
2024-11-21 13:51 |
2019-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211696
|
8.8 |
HIGH
Adjacent
|
audiocodes
|
median_500l-msbr_firmware median_500-msbr_firmware median_m800b-msbr_firmware median_800c-msbr_firmware
|
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An internal interface exposed to the link-local addres…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-9229
|
2024-11-21 13:51 |
2019-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211697
|
7.5 |
HIGH
Network
|
audiocodes
|
median_500l-msbr_firmware median_500-msbr_firmware median_m800b-msbr_firmware median_800c-msbr_firmware
|
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A at least to 7.20A.252.062. The (1) management SSH and (2) management …
|
NVD-CWE-noinfo
|
CVE-2019-9228
|
2024-11-21 13:51 |
2019-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211698
|
8.8 |
HIGH
Network
|
audiocodes
|
mediant_500l-msbr_firmware mediant_500-mbsr_firmware mediant_m800b-msbr_firmware mediant_800c-msbr_firmware
|
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions before 7.20A.202.307. A Cross-Site Request Forgery (CSRF) vulnerability in t…
|
CWE-352
Origin Validation Error
|
CVE-2019-9231
|
2024-11-21 13:51 |
2019-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211699
|
6.1 |
MEDIUM
Network
|
audiocodes
|
mediant_500l-msbr_firmware mediant_500-mbsr_firmware mediant_m800b-msbr_firmware mediant_800c-msbr_firmware
|
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.253. A cross-site scripting (XSS) vulnerability in the sear…
|
CWE-79
Cross-site Scripting
|
CVE-2019-9230
|
2024-11-21 13:51 |
2019-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211700
|
5.3 |
MEDIUM
Network
|
mailvelope
|
mailvelope
|
Mailvelope prior to 3.3.0 does not require user interaction to import public keys shown on web page. This functionality can be tricked to either hide a key import from the user or obscure which key w…
|
CWE-320
Key Management Errors
|
CVE-2019-9150
|
2024-11-21 13:51 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|