|
222181
|
9.8 |
CRITICAL
Network
|
samsung
|
samsung_firmware
|
Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or exe…
|
NVD-CWE-noinfo
|
CVE-2019-16256
|
2024-11-21 13:30 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222182
|
7.5 |
HIGH
Network
|
oceanwp
|
ocean_extra
|
includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading Style Sheets (CSS) token sequence.
|
CWE-287
Improper Authentication
|
CVE-2019-16250
|
2024-11-21 13:30 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222183
|
5.3 |
MEDIUM
Network
|
opencv
|
opencv
|
OpenCV 4.1.1 has an out-of-bounds read in hal_baseline::v_load in core/hal/intrin_sse.hpp when called from computeSSDMeanNorm in modules/video/src/dis_flow.cpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-16249
|
2024-11-21 13:30 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222184
|
5.5 |
MEDIUM
Local
|
telegram
|
telegram
|
The "delete for" feature in Telegram before 5.11 on Android does not delete shared media files from the Telegram Images directory. In other words, there is a potentially misleading UI indication that…
|
NVD-CWE-noinfo
|
CVE-2019-16248
|
2024-11-21 13:30 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222185
|
7.8 |
HIGH
Local
|
deltaww
|
dcisoft
|
Delta DCISoft 1.21 has a User Mode Write AV starting at CommLib!CCommLib::SetSerializeData+0x000000000000001b.
|
NVD-CWE-noinfo
|
CVE-2019-16247
|
2024-11-21 13:30 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222186
|
7.5 |
HIGH
Network
|
dino canonical fedoraproject debian
|
dino ubuntu_linux fedora debian_linux
|
Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep/0313_message_archive_management.vala.
|
CWE-346
Origin Validation Error
|
CVE-2019-16237
|
2024-11-21 13:30 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222187
|
7.5 |
HIGH
Network
|
dino canonical fedoraproject debian
|
dino ubuntu_linux fedora debian_linux
|
Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala.
|
CWE-862
Missing Authorization
|
CVE-2019-16236
|
2024-11-21 13:30 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222188
|
7.5 |
HIGH
Network
|
dino canonical fedoraproject debian
|
dino ubuntu_linux fedora debian_linux
|
Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep/0280_message_carbons.vala.
|
CWE-346
Origin Validation Error
|
CVE-2019-16235
|
2024-11-21 13:30 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222189
|
7.8 |
HIGH
Local
|
msi
|
afterburner
|
The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user to read and write to arbitrary memory, I/O ports, and MSRs. This can be exploite…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2019-16098
|
2024-11-21 13:30 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222190
|
4.7 |
MEDIUM
Local
|
linux canonical opensuse
|
linux_kernel ubuntu_linux leap
|
drivers/net/wireless/intel/iwlwifi/pcie/trans.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-16234
|
2024-11-21 13:30 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|