|
223691
|
6.5 |
MEDIUM
Network
|
un4seen
|
bass
|
The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Use after Free vulnerability via a crafted .ogg file. An attacker can exploit this to gain access to sensitive informat…
|
CWE-416
Use After Free
|
CVE-2019-18794
|
2024-11-21 13:33 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223692
|
5.4 |
MEDIUM
Adjacent
|
qualcomm
|
atheros_ar9132_firmware atheros_ar9283_firmware atheros_ar9285_firmware
|
A partial authentication bypass vulnerability exists on Atheros AR9132 3.60(AMX.8), AR9283 1.85, and AR9285 1.0.0.12NA devices. The vulnerability allows sending an unencrypted data frame to a WPA2-pr…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2019-18991
|
2024-11-21 13:33 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223693
|
5.4 |
MEDIUM
Adjacent
|
realtek
|
rtl8812ar_firmware rtl8196d_firmware rtl8192er_firmware rtl8881an_firmware
|
A partial authentication bypass vulnerability exists on Realtek RTL8812AR 1.21WW, RTL8196D 1.0.0, RTL8192ER 2.10, and RTL8881AN 1.09 devices. The vulnerability allows sending an unencrypted data fram…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2019-18990
|
2024-11-21 13:33 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223694
|
5.4 |
MEDIUM
Adjacent
|
mediatek
|
mt7620n_firmware
|
A partial authentication bypass vulnerability exists on Mediatek MT7620N 1.06 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is r…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2019-18989
|
2024-11-21 13:33 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223695
|
9.8 |
CRITICAL
Network
|
akamai
|
enterprise_application_access
|
Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1.
|
CWE-295
Improper Certificate Validation
|
CVE-2019-18847
|
2024-11-21 13:33 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223696
|
6.1 |
MEDIUM
Network
|
woocommerce
|
subscriptions
|
Persistent XSS in the WooCommerce Subscriptions plugin before 2.6.3 for WordPress allows remote attackers to execute arbitrary JavaScript because Billing Details are mishandled in WCS_Admin_Post_Type…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18834
|
2024-11-21 13:33 |
2020-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223697
|
7.8 |
HIGH
Local
|
synaptics lenovo hp
|
vfs75xx_firmware thinkpad_25_firmware thankpad_a475_firmware thankpad_a485_firmware thinkpad_e480_firmware thinkpad_e580_firmware thinkpad_e485_firmware thinkpad_e585_firmware
|
Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (…
|
CWE-763
Release of Invalid Pointer or Reference
|
CVE-2019-18619
|
2024-11-21 13:33 |
2020-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223698
|
6.0 |
MEDIUM
Local
|
synaptics lenovo hp
|
vfs75xx_firmware thinkpad_25_firmware thankpad_a475_firmware thankpad_a485_firmware thinkpad_e480_firmware thinkpad_e580_firmware thinkpad_e485_firmware thinkpad_e585_firmware
|
Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attack…
|
NVD-CWE-noinfo
|
CVE-2019-18618
|
2024-11-21 13:33 |
2020-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223699
|
7.8 |
HIGH
Local
|
cypress
|
cyw20735_firmware
|
On the Cypress CYW20735 evaluation board, any data that exceeds 384 bytes is copied and causes an overflow. This is because the maximum BLOC buffer size for sending and receiving data is set to 384 b…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-18614
|
2024-11-21 13:33 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223700
|
9.8 |
CRITICAL
Network
|
dlink
|
dap-1360_revision_f_firmware
|
An issue was discovered on D-Link DAP-1360 revision F devices. Remote attackers can start a telnet service without authorization via an undocumented HTTP request. Although this is the primary vulnera…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-18666
|
2024-11-21 13:33 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|