|
223311
|
9.1 |
CRITICAL
Network
|
microchip
|
advanced_software_framework_4
|
Atmel Advanced Software Framework (ASF) 4 has an Integer Overflow.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-16127
|
2024-11-21 13:30 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223312
|
7.5 |
HIGH
Network
|
mikrotik
|
routeros
|
An integer underflow in the SMB server of MikroTik RouterOS before 6.45.5 allows remote unauthenticated attackers to crash the service.
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2019-16160
|
2024-11-21 13:30 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223313
|
8.8 |
HIGH
Network
|
broadcom
|
brocade_sannav
|
A vulnerability in Brocade SANnav versions before v2.1.0 could allow a remote authenticated attacker to conduct an LDAP injection. The vulnerability could allow a remote attacker to bypass the authen…
|
NVD-CWE-Other
|
CVE-2019-16212
|
2024-11-21 13:30 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223314
|
9.8 |
CRITICAL
Network
|
broadcom
|
brocade_sannav
|
Brocade SANnav versions before v2.1.0, contain a Plaintext Password Storage vulnerability.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-16211
|
2024-11-21 13:30 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223315
|
9.8 |
CRITICAL
Network
|
pega
|
platform
|
Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. An attacker can specify four characters of a username, followed by the * charact…
|
NVD-CWE-Other
|
CVE-2019-16374
|
2024-11-21 13:30 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223316
|
9.8 |
CRITICAL
Network
|
openmicroscopy
|
omero.server
|
OMERO.server before 5.6.1 allows attackers to bypass the security filters and access hidden objects via a crafted query.
|
NVD-CWE-noinfo
|
CVE-2019-16244
|
2024-11-21 13:30 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223317
|
8.8 |
HIGH
Network
|
tendacn
|
pa6_firmware
|
Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted string, an attacker could modify th…
|
CWE-78
OS Command
|
CVE-2019-16213
|
2024-11-21 13:30 |
2020-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223318
|
5.3 |
MEDIUM
Network
|
openmicroscopy
|
omero
|
OMERO before 5.6.1 makes the details of each user available to all users.
|
NVD-CWE-noinfo
|
CVE-2019-16245
|
2024-11-21 13:30 |
2020-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223319
|
5.9 |
MEDIUM
Network
|
nutfind
|
nutfind
|
Missing SSL Certificate Validation in the Nutfind.com application through 3.9.12 for Android allows a man-in-the-middle attacker to sniff and manipulate all API requests, including login credentials …
|
CWE-295
Improper Certificate Validation
|
CVE-2019-16252
|
2024-11-21 13:30 |
2020-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223320
|
6.1 |
MEDIUM
Network
|
cybelesoft
|
thinfinity_virtualui
|
Cybele Thinfinity VirtualUI 2.5.17.2 allows HTTP response splitting via the mimetype parameter within a PDF viewer request, as demonstrated by an example.pdf?mimetype= substring. The victim user must…
|
CWE-79 CWE-74
Cross-site Scripting Injection
|
CVE-2019-16385
|
2024-11-21 13:30 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|