|
222411
|
7.0 |
HIGH
Local
|
linux canonical opensuse netapp broadcom debian
|
linux_kernel ubuntu_linux leap cloud_backup element_software steelstore_cloud_integrated_storage data_availability_services solidfire hci_management_node active_iq_unified_…
|
An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 ac…
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2019-18683
|
2024-11-21 13:33 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222412
|
7.5 |
HIGH
Network
|
linux
|
linux_kernel
|
An issue was discovered in the Linux kernel 4.4.x before 4.4.195. There is a NULL pointer dereference in rds_tcp_kill_sock() in net/rds/tcp.c that will cause denial of service, aka CID-91573ae4aed0.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-18680
|
2024-11-21 13:33 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222413
|
4.6 |
MEDIUM
Physics
|
shiftcrypto
|
bitbox02
|
On SHIFT BitBox02 devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a parti…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-18673
|
2024-11-21 13:33 |
2019-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222414
|
6.1 |
MEDIUM
Network
|
pfsense
|
pfsense-pkg-freeradius3
|
/usr/local/www/freeradius_view_config.php in the freeradius3 package before 0.15.7_3 for pfSense on FreeBSD allows a user with an XSS payload as password or username to execute arbitrary javascript c…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18667
|
2024-11-21 13:33 |
2019-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222415
|
7.5 |
HIGH
Network
|
secudos
|
domos
|
The Log module in SECUDOS DOMOS before 5.6 allows local file inclusion.
|
CWE-22
Path Traversal
|
CVE-2019-18665
|
2024-11-21 13:33 |
2019-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222416
|
5.4 |
MEDIUM
Network
|
secudos
|
domos
|
The Log module in SECUDOS DOMOS before 5.6 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-18664
|
2024-11-21 13:33 |
2019-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222417
|
7.5 |
HIGH
Network
|
fastweb
|
fastgate_firmware
|
Fastweb FASTGate 1.0.1b devices allow partial authentication bypass by changing a certain check_pwd return value from 0 to 1. An attack does not achieve administrative control of a device; however, t…
|
CWE-287
Improper Authentication
|
CVE-2019-18661
|
2024-11-21 13:33 |
2019-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222418
|
5.3 |
MEDIUM
Network
|
ready
|
wireless_emergency_alerts
|
The Wireless Emergency Alerts (WEA) protocol allows remote attackers to spoof a Presidential Alert because cryptographic authentication is not used, as demonstrated by MessageIdentifier 4370 in LTE S…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2019-18659
|
2024-11-21 13:33 |
2019-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222419
|
6.5 |
MEDIUM
Network
|
wpwham
|
currency_switcher_for_woocommerce
|
An issue was discovered in the Currency Switcher addon before 2.11.2 for WooCommerce if a user provides a currency that was not added by the administrator. In this case, even though the currency does…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2019-18668
|
2024-11-21 13:33 |
2019-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222420
|
9.8 |
CRITICAL
Network
|
youphptube
|
youphptube
|
An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plugin/LiveChat/getChat.json.php is not properly sanitized (in getFromChat in plug…
|
CWE-89
SQL Injection
|
CVE-2019-18662
|
2024-11-21 13:33 |
2019-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|