|
222451
|
7.8 |
HIGH
Local
|
verifone
|
mx900_firmware
|
Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow multiple arbitrary command injections, as demonstrated by the file manager.
|
CWE-77
Command Injection
|
CVE-2019-14719
|
2024-11-21 13:27 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222452
|
6.7 |
MEDIUM
Local
|
verifone
|
mx900_firmware
|
Verifone MX900 series Pinpad Payment Terminals with OS 30251000 have Insecure Permissions, with resultant svc_netcontrol arbitrary command injection and privilege escalation.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-14718
|
2024-11-21 13:27 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222453
|
7.8 |
HIGH
Local
|
verifone
|
verix_os
|
Verifone Verix OS on VerixV Pinpad Payment Terminals with QT000530 have a Buffer Overflow via the Run system call.
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-14717
|
2024-11-21 13:27 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222454
|
6.6 |
MEDIUM
Physics
|
verifone
|
verix_os
|
Verifone VerixV Pinpad Payment Terminals with QT000530 have an undocumented physical access mode (aka VerixV shell.out).
|
NVD-CWE-noinfo
|
CVE-2019-14716
|
2024-11-21 13:27 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222455
|
6.8 |
MEDIUM
Physics
|
verifone
|
p400_firmware p200_firmware vx_820_firmware vx_805_firmware
|
Verifone Pinpad Payment Terminals allow undocumented physical access to the system via an SBI bootloader memory write operation.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-14715
|
2024-11-21 13:27 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222456
|
5.5 |
MEDIUM
Local
|
verifone
|
mx900_firmware
|
Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow installation of unsigned packages.
|
NVD-CWE-noinfo
|
CVE-2019-14713
|
2024-11-21 13:27 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222457
|
7.8 |
HIGH
Local
|
verifone
|
verix_os
|
Verifone VerixV Pinpad Payment Terminals with QT000530 allow bypass of integrity and origin control for S1G file generation.
|
NVD-CWE-noinfo
|
CVE-2019-14712
|
2024-11-21 13:27 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222458
|
7.0 |
HIGH
Local
|
verifone
|
mx900_firmware
|
Verifone MX900 series Pinpad Payment Terminals with OS 30251000 have a race condition for RBAC bypass.
|
CWE-362
Race Condition
|
CVE-2019-14711
|
2024-11-21 13:27 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222459
|
4.4 |
MEDIUM
Local
|
kaiostech
|
kaios
|
An issue was discovered in KaiOS 2.5. The pre-installed Note application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the Note application. …
|
CWE-79
Cross-site Scripting
|
CVE-2019-14761
|
2024-11-21 13:27 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222460
|
4.4 |
MEDIUM
Local
|
kaiostech
|
kaios
|
An issue was discovered in KaiOS 2.5. The pre-installed Recorder application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the Recorder appli…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14760
|
2024-11-21 13:27 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|