|
224251
|
9.8 |
CRITICAL
Network
|
netgear
|
mbr1515_firmware mbr1516_firmware dgn2200_firmware dgn2200m_firmware dgnd3700_firmware wnr2000v2_firmware wndr3300_firmware wndr3400_firmware wnr3500_firmware wnr834bv2_fir…
|
Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg to a URL. This affects MBR1515, MBR1516, DGN2200, …
|
NVD-CWE-noinfo
|
CVE-2019-17373
|
2024-11-21 13:32 |
2019-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224252
|
8.1 |
HIGH
Network
|
netgear
|
ac1450_firmware d8500_firmware dc112a_firmware jndr3000_firmware lg2200d_firmware r4500_firmware r6200_firmware r6200v2_firmware r6250_firmware r6300_firmware r6300v2_fi…
|
Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can then, for example, visit MNU_accessPassword_recovere…
|
CWE-287
Improper Authentication
|
CVE-2019-17372
|
2024-11-21 13:32 |
2019-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224253
|
6.5 |
MEDIUM
Network
|
gif2png_project
|
gif2png
|
gif2png 2.5.13 has a memory leak in the writefile function.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-17371
|
2024-11-21 13:32 |
2019-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224254
|
7.2 |
HIGH
Network
|
otcms
|
otcms
|
OTCMS v3.85 allows arbitrary PHP Code Execution because admin/sysCheckFile_deal.php blocks "into outfile" in a SELECT statement, but does not block the "into/**/outfile" manipulation. Therefore, the …
|
CWE-89
SQL Injection
|
CVE-2019-17370
|
2024-11-21 13:32 |
2019-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224255
|
9.4 |
CRITICAL
Network
|
zyxel
|
nbg-418n_v2_firmware
|
wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be lev…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-17354
|
2024-11-21 13:32 |
2019-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224256
|
8.2 |
HIGH
Network
|
dlink
|
dir-615_firmware
|
An issue discovered on D-Link DIR-615 devices with firmware version 20.05 and 20.07. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-17353
|
2024-11-21 13:32 |
2019-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224257
|
6.5 |
MEDIUM
Network
|
otcms
|
otcms
|
OTCMS v3.85 has CSRF in the admin/member_deal.php Admin Panel page, leading to creation of a new management group account, as demonstrated by superadmin.
|
CWE-352
Origin Validation Error
|
CVE-2019-17369
|
2024-11-21 13:32 |
2019-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224258
|
6.1 |
MEDIUM
Network
|
s-cms
|
s-cms
|
S-CMS v1.5 has XSS in tpl.php via the member/member_login.php from parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17368
|
2024-11-21 13:32 |
2019-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224259
|
9.1 |
CRITICAL
Network
|
libtom debian
|
libtomcrypt debian_linux
|
In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 sequences. This allows context-dependent attackers to c…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-17362
|
2024-11-21 13:32 |
2019-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224260
|
7.5 |
HIGH
Network
|
bouncycastle apache netapp oracle
|
legion-of-the-bouncy-castle-java-crytography-api tomee oncommand_workflow_automation service_level_manager oncommand_api_services active_iq_unified_manager flexcube_private_banking<…
|
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-17359
|
2024-11-21 13:32 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|