|
220991
|
9.8 |
CRITICAL
Network
|
moxa
|
iks-g6824a_firmware eds-405a_firmware eds-408a_firmware eds-510a_firmware
|
Several buffer overflow vulnerabilities have been identified in Moxa IKS and EDS, which may allow remote code execution.
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-6557
|
2024-11-21 13:46 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220992
|
9.8 |
CRITICAL
Network
|
moxa
|
iks-g6824a_firmware eds-405a_firmware eds-408a_firmware eds-510a_firmware
|
Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allow an attacker to discover passwords via brute force attack.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2019-6524
|
2024-11-21 13:46 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220993
|
9.1 |
CRITICAL
Network
|
moxa
|
iks-g6824a_firmware eds-405a_firmware eds-408a_firmware eds-510a_firmware
|
Moxa IKS and EDS fails to properly check array bounds which may allow an attacker to read device memory on arbitrary addresses, and may allow an attacker to retrieve sensitive data or cause device re…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-6522
|
2024-11-21 13:46 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220994
|
8.8 |
HIGH
Network
|
psigridconnect
|
telecontrol_gateway_xs-mu_firmware telecontrol_gateway_vm_firmware telecontrol_gateway_3g_firmware smart_telecontrol_unit_tcg_firmware iec104_security_proxy_firmware
|
PSI GridConnect GmbH Telecontrol Gateway and Smart Telecontrol Unit family, IEC104 Security Proxy versions Telecontrol Gateway 3G Versions 4.2.21, 5.0.27, 5.1.19, 6.0.16 and prior, and Telecontrol Ga…
|
CWE-79
Cross-site Scripting
|
CVE-2019-6528
|
2024-11-21 13:46 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220995
|
7.5 |
HIGH
Network
|
moxa
|
iks-g6824a_firmware eds-405a_firmware eds-408a_firmware eds-510a_firmware
|
Moxa IKS and EDS does not properly check authority on server side, which results in a read-only user being able to perform arbitrary configuration changes.
|
NVD-CWE-Other
|
CVE-2019-6520
|
2024-11-21 13:46 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220996
|
7.5 |
HIGH
Network
|
moxa
|
iks-g6824a_firmware eds-405a_firmware eds-408a_firmware eds-510a_firmware
|
Moxa IKS and EDS store plaintext passwords, which may allow sensitive information to be read by someone with access to the device.
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2019-6518
|
2024-11-21 13:46 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220997
|
8.8 |
HIGH
Network
|
apple webkitgtk
|
iphone_os safari tvos icloud itunes webkitgtk\+
|
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing ma…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-6234
|
2024-11-21 13:46 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220998
|
8.8 |
HIGH
Network
|
apple
|
iphone_os safari tvos icloud itunes
|
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing ma…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-6233
|
2024-11-21 13:46 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220999
|
5.5 |
MEDIUM
Local
|
apple
|
iphone_os mac_os_x watchos tvos
|
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to read res…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-6231
|
2024-11-21 13:46 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221000
|
8.6 |
HIGH
Local
|
apple
|
iphone_os mac_os_x watchos tvos
|
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3,macOS Mojave 10.14.3,tvOS 12.1.2,watchOS 5.1.3. A malicious application may be able to bre…
|
CWE-665
Improper Initialization
|
CVE-2019-6230
|
2024-11-21 13:46 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|