|
222101
|
9.8 |
CRITICAL
Network
|
beckhoff
|
twincat
|
Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remote Code Execution (as SYSTEM) via the Beckhoff ADS protocol.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2019-16871
|
2024-11-21 13:31 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222102
|
5.9 |
MEDIUM
Network
|
rack_project fedoraproject opensuse
|
rack fedora leap
|
There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched in versions 1.6.12 and 2.0.8. Attackers may be able to find and hijack session…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-16782
|
2024-11-21 13:31 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222103
|
9.8 |
CRITICAL
Network
|
google
|
tensorflow
|
In TensorFlow before 1.15, a heap buffer overflow in UnsortedSegmentSum can be produced when the Index template argument is int32. In this case data_size and num_segments fields are truncated from in…
|
CWE-681
Incorrect Conversion between Numeric Types
|
CVE-2019-16778
|
2024-11-21 13:31 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222104
|
5.9 |
MEDIUM
Network
|
excon_project opensuse debian
|
excon leap backports_sle debian_linux
|
In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent req…
|
CWE-362
Race Condition
|
CVE-2019-16779
|
2024-11-21 13:31 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222105
|
9.8 |
CRITICAL
Network
|
skymee petwant
|
petalk_ai_firmware pf-103_firmware
|
The processCommandSetMac() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.
|
CWE-78
OS Command
|
CVE-2019-16737
|
2024-11-21 13:31 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222106
|
9.8 |
CRITICAL
Network
|
skymee petwant
|
petalk_ai_firmware pf-103_firmware
|
A stack-based buffer overflow in processCommandUploadSnapshot in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to cause denial of service or run arb…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-16736
|
2024-11-21 13:31 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222107
|
9.8 |
CRITICAL
Network
|
skymee petwant
|
petalk_ai_firmware pf-103_firmware
|
A stack-based buffer overflow in processCommandUploadLog in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to cause denial of service or run arbitrar…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-16735
|
2024-11-21 13:31 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222108
|
9.8 |
CRITICAL
Network
|
skymee petwant
|
petalk_ai_firmware pf-103_firmware
|
Use of default credentials for the TELNET server in Petwant PF-103 firmware 4.3.2.50 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-16734
|
2024-11-21 13:31 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222109
|
9.8 |
CRITICAL
Network
|
skymee petwant
|
petalk_ai_firmware pf-103_firmware
|
processCommandSetUid() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.
|
CWE-78
OS Command
|
CVE-2019-16733
|
2024-11-21 13:31 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222110
|
8.1 |
HIGH
Network
|
skymee petwant
|
petalk_ai_firmware pf-103_firmware
|
Unencrypted HTTP communications for firmware upgrades in Petalk AI and PF-103 allow man-in-the-middle attackers to run arbitrary code as the root user.
|
CWE-347 CWE-319
Improper Verification of Cryptographic Signature Cleartext Transmission of Sensitive Information
|
CVE-2019-16732
|
2024-11-21 13:31 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|