|
211271
|
6.1 |
MEDIUM
Network
|
paessler
|
prtg_network_monitor
|
PRTG Network Monitor v7.1.3.3378 allows XSS via the /public/login.htm errormsg or loginurl parameter. NOTE: This product is discontinued.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9206
|
2024-11-21 13:51 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211272
|
8.8 |
HIGH
Network
|
unity3d
|
unity_editor
|
The com.unity3d.kharma protocol handler in Unity Editor 2018.3 allows remote attackers to execute arbitrary code.
|
CWE-78
OS Command
|
CVE-2019-9197
|
2024-11-21 13:51 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211273
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In various functions of RecentLocationApps.java, DevicePolicyManagerService.java, and RecognitionService.java, there is an incorrect warning indicating an app accessed the user's location. This could…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-9464
|
2024-11-21 13:51 |
2019-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211274
|
6.8 |
MEDIUM
Physics
|
apple
|
iphone_3gs
|
Apple iPhone 3GS bootrom malloc implementation returns a non-NULL pointer when unable to allocate memory, aka 'alloc8'. An attacker with physical access to the device can install arbitrary firmware.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2019-9536
|
2024-11-21 13:51 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211275
|
6.7 |
MEDIUM
Local
|
google
|
android
|
In the Bootloader, there is a possible kernel command injection due to missing command sanitization. This could lead to a local elevation of privilege with System execution privileges needed. User in…
|
CWE-20 CWE-77
Improper Input Validation Command Injection
|
CVE-2019-9467
|
2024-11-21 13:51 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211276
|
6.5 |
MEDIUM
Network
|
darktrace
|
enterprise_immune_system
|
Darktrace Enterprise Immune System before 3.1 allows CSRF via the /config endpoint.
|
CWE-352
Origin Validation Error
|
CVE-2019-9597
|
2024-11-21 13:51 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211277
|
6.5 |
MEDIUM
Network
|
darktrace
|
enterprise_immune_system
|
Darktrace Enterprise Immune System before 3.1 allows CSRF via the /whitelisteddomains endpoint.
|
CWE-352
Origin Validation Error
|
CVE-2019-9596
|
2024-11-21 13:51 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211278
|
7.8 |
HIGH
Local
|
trendmicro
|
anti-threat_toolkit
|
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary …
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-9491
|
2024-11-21 13:51 |
2019-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211279
|
7.8 |
HIGH
Local
|
cobham
|
explorer_710_firmware
|
The Cobham EXPLORER 710, firmware version 1.07, does not validate its firmware image. Development scripts left in the firmware can be used to upload a custom firmware image that the device runs. This…
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2019-9534
|
2024-11-21 13:51 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211280
|
9.8 |
CRITICAL
Network
|
cobham
|
explorer_710_firmware
|
The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08. This could allow an attacker to reverse-engineer the password from available versions …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-9533
|
2024-11-21 13:51 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|