|
218691
|
8.1 |
HIGH
Network
|
teradata
|
viewpoint
|
Teradata Viewpoint before 14.0 and 16.20.00.02-b80 contains a hardcoded password of TDv1i2e3w4 for the viewpoint database account (in viewpoint-portal\conf\server.xml) that could potentially be explo…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-6499
|
2024-11-21 13:46 |
2019-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218692
|
8.8 |
HIGH
Adjacent
|
labapart
|
gattlib
|
GattLib 0.2 has a stack-based buffer over-read in gattlib_connect in dbus/gattlib.c because strncpy is misused.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-6498
|
2024-11-21 13:46 |
2019-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218693
|
9.8 |
CRITICAL
Network
|
hotels_server_project
|
hotels_server
|
Hotels_Server through 2018-11-05 has SQL Injection via the controller/fetchpwd.php username parameter.
|
CWE-89
SQL Injection
|
CVE-2019-6497
|
2024-11-21 13:46 |
2019-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218694
|
7.8 |
HIGH
Local
|
gnu
|
glibc
|
The string component in the GNU C Library (aka glibc or libc6) through 2.28, when running on the x32 architecture, incorrectly attempts to use a 64-bit register for size_t in assembly codes, which ca…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2019-6488
|
2024-11-21 13:46 |
2019-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218695
|
9.8 |
CRITICAL
Network
|
aspeedtech netapp
|
ast2400_firmware ast2500_firmware fas\/aff_baseboard_management_controller
|
The ASPEED ast2400 and ast2500 Baseband Management Controller (BMC) hardware and firmware implement Advanced High-performance Bus (AHB) bridges, which allow arbitrary read and write access to the BMC…
|
NVD-CWE-noinfo
|
CVE-2019-6260
|
2024-11-21 13:46 |
2019-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218696
|
9.8 |
CRITICAL
Network
|
drupal debian
|
drupal debian_linux
|
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file opera…
|
CWE-20
Improper Input Validation
|
CVE-2019-6339
|
2024-11-21 13:46 |
2019-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218697
|
8.8 |
HIGH
Adjacent
|
marvell
|
88w8787_firmware 88w8797_firmware 88w8801_firmware 88w8897_firmware 88w8997_firmware
|
The ThreadX-based firmware on Marvell Avastar Wi-Fi devices, models 88W8787, 88W8797, 88W8801, 88W8897, and 88W8997, allows remote attackers to execute arbitrary code or cause a denial of service (bl…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-6496
|
2024-11-21 13:46 |
2019-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218698
|
8.8 |
HIGH
Network
|
tp-link
|
tl-wdr5620_firmware tl-wdr3500_firmware tl-wdr3600_firmware tl-wdr4300_firmware tl-wdr4900_firmware
|
TP-Link WDR Series devices through firmware v3 (such as TL-WDR5620 V3.0) are affected by command injection (after login) leading to remote code execution, because shell metacharacters can be included…
|
CWE-78
OS Command
|
CVE-2019-6487
|
2024-11-21 13:46 |
2019-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218699
|
6.5 |
MEDIUM
Network
|
cairographics
|
cairo
|
An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-6462
|
2024-11-21 13:46 |
2019-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218700
|
6.5 |
MEDIUM
Network
|
cairographics
|
cairo
|
An issue was discovered in cairo 1.16.0. There is an assertion problem in the function _cairo_arc_in_direction in the file cairo-arc.c.
|
CWE-617
Reachable Assertion
|
CVE-2019-6461
|
2024-11-21 13:46 |
2019-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|