|
221971
|
9.4 |
CRITICAL
Network
|
zyxel
|
nbg-418n_v2_firmware
|
wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be lev…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-17354
|
2024-11-21 13:32 |
2019-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221972
|
8.2 |
HIGH
Network
|
dlink
|
dir-615_firmware
|
An issue discovered on D-Link DIR-615 devices with firmware version 20.05 and 20.07. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-17353
|
2024-11-21 13:32 |
2019-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221973
|
6.5 |
MEDIUM
Network
|
otcms
|
otcms
|
OTCMS v3.85 has CSRF in the admin/member_deal.php Admin Panel page, leading to creation of a new management group account, as demonstrated by superadmin.
|
CWE-352
Origin Validation Error
|
CVE-2019-17369
|
2024-11-21 13:32 |
2019-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221974
|
6.1 |
MEDIUM
Network
|
s-cms
|
s-cms
|
S-CMS v1.5 has XSS in tpl.php via the member/member_login.php from parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17368
|
2024-11-21 13:32 |
2019-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221975
|
9.1 |
CRITICAL
Network
|
libtom debian
|
libtomcrypt debian_linux
|
In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 sequences. This allows context-dependent attackers to c…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-17362
|
2024-11-21 13:32 |
2019-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221976
|
7.5 |
HIGH
Network
|
bouncycastle apache netapp oracle
|
legion-of-the-bouncy-castle-java-crytography-api tomee oncommand_workflow_automation service_level_manager oncommand_api_services active_iq_unified_manager flexcube_private_banking<…
|
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-17359
|
2024-11-21 13:32 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221977
|
7.5 |
HIGH
Network
|
jfinal
|
jfinal
|
In JFinal cos before 2019-08-13, as used in JFinal 4.4, there is a vulnerability that can bypass the isSafeFile() function: one can upload any type of file. For example, a .jsp file may be stored and…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-17352
|
2024-11-21 13:32 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221978
|
4.9 |
MEDIUM
Network
|
vbulletin
|
vbulletin
|
vBulletin 5.5.4 allows SQL Injection via the ajax/api/hook/getHookList or ajax/api/widget/getWidgetList where parameter.
|
CWE-89
SQL Injection
|
CVE-2019-17271
|
2024-11-21 13:32 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221979
|
5.5 |
MEDIUM
Local
|
xen debian
|
xen debian_linux
|
An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of service (infinite loop) involving a LoadExcl or StoreExcl operation.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-17349
|
2024-11-21 13:32 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221980
|
6.5 |
MEDIUM
Local
|
xen debian
|
xen debian_linux
|
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service because of an incompatibility between Process Context Identifiers (PCID) and shadow-pagetable…
|
CWE-20
Improper Input Validation
|
CVE-2019-17348
|
2024-11-21 13:32 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|