|
223431
|
8.8 |
HIGH
Network
|
sagemcom netgear technicolor compal
|
f\@st_3890_firmware f\@st_3686_firmware cg3700emr_firmware c6250emr_firmware tc7230_steb_firmware 7284e_firmware 7486e_firmware
|
Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrary code at the kernel level via JavaScript run in a victim's …
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-19494
|
2024-11-21 13:34 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223432
|
9.8 |
CRITICAL
Network
|
technicolor
|
tc7230_steb_firmware
|
The web interface on the Technicolor TC7230 STEB 01.25 is vulnerable to DNS rebinding, which allows a remote attacker to configure the cable modem via JavaScript in a victim's browser. The attacker c…
|
CWE-20
Improper Input Validation
|
CVE-2019-19495
|
2024-11-21 13:34 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223433
|
7.8 |
HIGH
Local
|
broadcom
|
ca_automic_dollar_universe
|
CA Automic Dollar Universe 5.3.3 contains a vulnerability, related to the uxdqmsrv binary being setuid root, that allows local attackers to elevate privileges. This vulnerability was reported to CA s…
|
CWE-269
Improper Privilege Management
|
CVE-2019-19544
|
2024-11-21 13:34 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223434
|
9.8 |
CRITICAL
Network
|
broadcom
|
ca_automic_sysload
|
CA Automic Sysload 5.6.0 through 6.1.2 contains a vulnerability, related to a lack of authentication on the File Server port, that potentially allows remote attackers to execute arbitrary commands.
|
CWE-287
Improper Authentication
|
CVE-2019-19518
|
2024-11-21 13:34 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223435
|
7.8 |
HIGH
Local
|
rconfig
|
rconfig
|
An issue was discovered in rConfig 3.9.3. The install script updates the /etc/sudoers file for rconfig specific tasks. After an "rConfig specific Apache configuration" update, apache has high privile…
|
CWE-269
Improper Privilege Management
|
CVE-2019-19585
|
2024-11-21 13:34 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223436
|
8.8 |
HIGH
Network
|
rconfig
|
rconfig
|
An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a GET request to ajaxArchiveFiles.php because the path parameter is passed to the…
|
CWE-78
OS Command
|
CVE-2019-19509
|
2024-11-21 13:34 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223437
|
6.1 |
MEDIUM
Network
|
icewarp
|
mail_server
|
IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 1 of 2) in notes for contacts.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19265
|
2024-11-21 13:34 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223438
|
5.4 |
MEDIUM
Network
|
icewarp
|
mail_server
|
IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 2 of 2) in notes for objects.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19266
|
2024-11-21 13:34 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223439
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2019-19314
|
2024-11-21 13:34 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223440
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible to create, edit, or view issues and commits.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2019-19313
|
2024-11-21 13:34 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|