|
218841
|
8.8 |
HIGH
Network
|
xcftools_project debian
|
xcftools debian_linux
|
An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools 1.0.7. An integer overflow can occur while calculating the ro…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2019-5087
|
2024-11-21 13:44 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218842
|
8.8 |
HIGH
Network
|
xcftools_project debian
|
xcftools debian_linux
|
An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools, version 1.0.7. An integer overflow can occur while walking t…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2019-5086
|
2024-11-21 13:44 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218843
|
5.9 |
MEDIUM
Network
|
openwrt
|
openwrt
|
An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote server, the server's SSL certificate is checked b…
|
-
|
CVE-2019-5102
|
2024-11-21 13:44 |
2019-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218844
|
5.9 |
MEDIUM
Network
|
openwrt
|
openwrt
|
An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote server, the server's SSL certificate is checked b…
|
-
|
CVE-2019-5101
|
2024-11-21 13:44 |
2019-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218845
|
9.8 |
CRITICAL
Network
|
exhibitor_project
|
exhibitor
|
An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands surrounded by backticks or $() can be inserted int…
|
CWE-78
OS Command
|
CVE-2019-5029
|
2024-11-21 13:44 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218846
|
7.5 |
HIGH
Network
|
huawei
|
ar120-s_firmware ar1200_firmware ar1200-s_firmware ar150_firmware ar150-s_firmware ar160_firmware ar200_firmware ar200-s_firmware ar2200_firmware ar2200-s_firmware ar320…
|
There is an out of bound read vulnerability in some Huawei products. A remote, unauthenticated attacker may send a corrupt or crafted message to the affected products. Due to a buffer read overflow e…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-5294
|
2024-11-21 13:44 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218847
|
6.5 |
MEDIUM
Network
|
huawei
|
ar120-s_firmware ar1200_firmware ar1200-s_firmware ar150_firmware ar150-s_firmware ar160_firmware ar200_firmware ar200-s_firmware ar2200_firmware ar2200-s_firmware ar320…
|
Some Huawei products have a memory leak vulnerability when handling some messages. A remote attacker with operation privilege could exploit the vulnerability by sending specific messages continuously…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-5293
|
2024-11-21 13:44 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218848
|
7.5 |
HIGH
Network
|
huawei
|
manageone
|
Gauss100 OLTP database in ManageOne with versions of 6.5.0 have an out-of-bounds read vulnerability due to the insufficient checks of the specific packet length. Attackers can construct invalid packe…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-5289
|
2024-11-21 13:44 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218849
|
3.3 |
LOW
Local
|
huawei
|
honor_10_lite_firmware honor_8a_firmware huawei_y6_firmware
|
Honor 10 Lite, Honor 8A, Huawei Y6 mobile phones with the versions before 9.1.0.217(C00E215R3P1), the versions before 9.1.0.205(C00E97R1P9), the versions before 9.1.0.205(C00E97R2P2) have an informat…
|
NVD-CWE-noinfo
|
CVE-2019-5292
|
2024-11-21 13:44 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218850
|
7.8 |
HIGH
Local
|
huawei
|
p30_firmware
|
P30 smart phones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an integer overflow vulnerability due to insufficient check on specific parameters. An attacker tricks the user into…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-5288
|
2024-11-21 13:44 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|