|
222101
|
9.8 |
CRITICAL
Network
|
sparkdevnetwork
|
rock_rms
|
Rock RMS version before 8.6 is vulnerable to account takeover by tampering with the user ID parameter in the profile update feature. The lack of validation and use of sequential user IDs allows any u…
|
NVD-CWE-noinfo
|
CVE-2019-18642
|
2024-11-21 13:33 |
2021-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222102
|
6.5 |
MEDIUM
Network
|
un4seen
|
bass
|
The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Denial of Service vulnerability (infinite loop) via a crafted .mp3 file. This weakness could allow attackers to consume…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-18796
|
2024-11-21 13:33 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222103
|
6.5 |
MEDIUM
Network
|
un4seen
|
bass
|
The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile out of bounds read vulnerability via a crafted .wav file. An attacker can exploit this issues to gain access to sensiti…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-18795
|
2024-11-21 13:33 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222104
|
6.5 |
MEDIUM
Network
|
un4seen
|
bass
|
The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Use after Free vulnerability via a crafted .ogg file. An attacker can exploit this to gain access to sensitive informat…
|
CWE-416
Use After Free
|
CVE-2019-18794
|
2024-11-21 13:33 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222105
|
5.4 |
MEDIUM
Adjacent
|
qualcomm
|
atheros_ar9132_firmware atheros_ar9283_firmware atheros_ar9285_firmware
|
A partial authentication bypass vulnerability exists on Atheros AR9132 3.60(AMX.8), AR9283 1.85, and AR9285 1.0.0.12NA devices. The vulnerability allows sending an unencrypted data frame to a WPA2-pr…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2019-18991
|
2024-11-21 13:33 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222106
|
5.4 |
MEDIUM
Adjacent
|
realtek
|
rtl8812ar_firmware rtl8196d_firmware rtl8192er_firmware rtl8881an_firmware
|
A partial authentication bypass vulnerability exists on Realtek RTL8812AR 1.21WW, RTL8196D 1.0.0, RTL8192ER 2.10, and RTL8881AN 1.09 devices. The vulnerability allows sending an unencrypted data fram…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2019-18990
|
2024-11-21 13:33 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222107
|
5.4 |
MEDIUM
Adjacent
|
mediatek
|
mt7620n_firmware
|
A partial authentication bypass vulnerability exists on Mediatek MT7620N 1.06 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is r…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2019-18989
|
2024-11-21 13:33 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222108
|
9.8 |
CRITICAL
Network
|
akamai
|
enterprise_application_access
|
Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1.
|
CWE-295
Improper Certificate Validation
|
CVE-2019-18847
|
2024-11-21 13:33 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222109
|
6.1 |
MEDIUM
Network
|
woocommerce
|
subscriptions
|
Persistent XSS in the WooCommerce Subscriptions plugin before 2.6.3 for WordPress allows remote attackers to execute arbitrary JavaScript because Billing Details are mishandled in WCS_Admin_Post_Type…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18834
|
2024-11-21 13:33 |
2020-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222110
|
7.8 |
HIGH
Local
|
synaptics lenovo hp
|
vfs75xx_firmware thinkpad_25_firmware thankpad_a475_firmware thankpad_a485_firmware thinkpad_e480_firmware thinkpad_e580_firmware thinkpad_e485_firmware thinkpad_e585_firmware
|
Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (…
|
CWE-763
Release of Invalid Pointer or Reference
|
CVE-2019-18619
|
2024-11-21 13:33 |
2020-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|