|
221701
|
4.6 |
MEDIUM
Physics
|
harman
|
hermes
|
An authentication bypass in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with physical access to device hardware to obtain system information.
|
CWE-287
Improper Authentication
|
CVE-2019-19562
|
2024-11-21 13:34 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221702
|
2.4 |
LOW
Physics
|
harman
|
hermes
|
A misconfiguration in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with direct physical access to device hardware to obtain cellular modem information.
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2019-19561
|
2024-11-21 13:34 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221703
|
4.6 |
MEDIUM
Physics
|
harman
|
hermes
|
An authentication bypass in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with physical access to device hardware to obtain system information.
|
CWE-287
Improper Authentication
|
CVE-2019-19560
|
2024-11-21 13:34 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221704
|
2.4 |
LOW
Physics
|
harman
|
hermes
|
A misconfiguration in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with direct physical access to device hardware to obtain cellular modem information.
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2019-19557
|
2024-11-21 13:34 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221705
|
4.6 |
MEDIUM
Physics
|
harman
|
hermes
|
An authentication bypass in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with physical access to device hardware to obtain system information.
|
NVD-CWE-noinfo
|
CVE-2019-19556
|
2024-11-21 13:34 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221706
|
9.8 |
CRITICAL
Network
|
un4seen
|
bassmidi
|
The BASSMIDI plugin 2.4.12.1 for Un4seen BASS Audio Library on Windows is prone to an out of bounds write vulnerability. An attacker may exploit this to execute code on the target machine. A failure …
|
CWE-787
Out-of-bounds Write
|
CVE-2019-19513
|
2024-11-21 13:34 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221707
|
7.8 |
HIGH
Local
|
nahimic
|
apo_software_component
|
An escalation of privilege vulnerability in Nahimic APO Software Component Driver 1.4.2, 1.5.0, 1.5.1, 1.6.1 and 1.6.2 allows an attacker to execute code with SYSTEM privileges.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-19115
|
2024-11-21 13:34 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221708
|
8.8 |
HIGH
Network
|
reddoxx
|
maildepot
|
REDDOXX MailDepot 2032 2.2.1242 allows authenticated users to access the mailboxes of other users.
|
CWE-863
Incorrect Authorization
|
CVE-2019-19200
|
2024-11-21 13:34 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221709
|
7.4 |
HIGH
Network
|
reddoxx
|
maildepot
|
REDDOXX MailDepot 2032 SP2 2.2.1242 has Insufficient Session Expiration because tokens are not invalidated upon a logout.
|
CWE-613
Insufficient Session Expiration
|
CVE-2019-19199
|
2024-11-21 13:34 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221710
|
6.1 |
MEDIUM
Network
|
rittal
|
cmc_pu_iii_7030.000_firmware
|
The Web application on Rittal CMC PU III 7030.000 V3.00 V3.11.00_2 to V3.15.70_4 devices fails to sanitize user input on the system configurations page. This allows an attacker to backdoor the device…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19393
|
2024-11-21 13:34 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|