|
223711
|
7.5 |
HIGH
Network
|
senior
|
rubiweb
|
Remote Authentication Bypass in Senior Rubiweb 6.2.34.28 and 6.2.34.37 allows admin access to sensitive information of affected users using vulnerable versions. The attacker only needs to provide the…
|
CWE-200
Information Exposure
|
CVE-2019-19550
|
2024-11-21 13:34 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223712
|
5.5 |
MEDIUM
Local
|
hp
|
web_viewpoint_t0320 web_viewpoint_t0952 web_viewpoint_t0986
|
An issue was discovered in Idelji Web ViewPoint H01ABO-H01BY and L01ABP-L01ABZ, Web ViewPoint Plus H01AAG-H01AAQ and L01AAH-L01AAR, and Web ViewPoint Enterprise H01-H01AAE and L01-L01AAF. By reading …
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-19539
|
2024-11-21 13:34 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223713
|
6.1 |
MEDIUM
Adjacent
|
tp-link
|
tl-wr849n_firmware
|
TP-LINK TL-WR849N 0.9.1 4.16 devices do not require authentication to replace the firmware via a POST request to the cgi/softup URI.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-19143
|
2024-11-21 13:34 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223714
|
7.8 |
HIGH
Local
|
ricoh
|
ps_driver_for_universal_print pcl6_driver_for_universal_print rpcs_driver postscript3_driver pcl6_\(pcl_xl\)_driver pc_fax_generic_driver generic_pcl5_driver rpcs_raster_driver
|
An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attackers local privilege escalation. Affected drivers and versions are: PCL6 Driver fo…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-19363
|
2024-11-21 13:34 |
2020-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223715
|
7.5 |
HIGH
Network
|
huawei
|
dbs3900_tdd_lte_firmware dp300_firmware rp200_firmware te30_firmware te40_firmware te50_firmware te60_firmware
|
There is an integer overflow vulnerability in LDAP server of some Huawei products. Due to insufficient input validation, a remote attacker could exploit this vulnerability by sending malformed packet…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-19414
|
2024-11-21 13:34 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223716
|
7.5 |
HIGH
Network
|
huawei
|
dbs3900_tdd_lte_firmware dp300_firmware rp200_firmware te30_firmware te40_firmware te50_firmware te60_firmware
|
There is an integer overflow vulnerability in LDAP client of some Huawei products. Due to insufficient input validation, a remote attacker could exploit this vulnerability by sending malformed packet…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-19413
|
2024-11-21 13:34 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223717
|
3.7 |
LOW
Network
|
huawei
|
usg9500_firmware
|
USG9500 with versions of V500R001C30SPC100, V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200 have an information leakage vulnerability. Due to improper pr…
|
CWE-665
Improper Initialization
|
CVE-2019-19411
|
2024-11-21 13:34 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223718
|
6.5 |
MEDIUM
Network
|
samba canonical synology opensuse
|
samba ubuntu_linux skynas diskstation_manager directory_server router_manager leap
|
There is a use-after-free issue in all samba 4.9.x versions before 4.9.18, all samba 4.10.x versions before 4.10.12 and all samba 4.11.x versions before 4.11.5, essentially due to a call to realloc()…
|
CWE-416
Use After Free
|
CVE-2019-19344
|
2024-11-21 13:34 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223719
|
9.8 |
CRITICAL
Network
|
fordnn
|
usersexportimport
|
The forDNN.UsersExportImport module before 1.2.0 for DNN (formerly DotNetNuke) allows an unprivileged user to import (create) new users with Administrator privileges, as demonstrated by Roles="Admini…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-19392
|
2024-11-21 13:34 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223720
|
6.5 |
MEDIUM
Local
|
redhat
|
enterprise_linux enterprise_linux_eus
|
It was found that the Red Hat Enterprise Linux 8 kpatch update did not include the complete fix for CVE-2018-12207. A flaw was found in the way Intel CPUs handle inconsistency between, virtual to phy…
|
NVD-CWE-noinfo
|
CVE-2019-19339
|
2024-11-21 13:34 |
2020-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|