|
224151
|
5.4 |
MEDIUM
Network
|
openwrt
|
openwrt
|
OpenWrt 18.06.4 allows XSS via these Name fields to the cgi-bin/luci/admin/network/firewall/rules URI: "Open ports on router" and "New forward rule" and "New Source NAT" (this can occur, for example,…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18992
|
2024-11-21 13:33 |
2019-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224152
|
9.8 |
CRITICAL
Network
|
titanhq
|
webtitan
|
An issue was discovered in TitanHQ WebTitan before 5.18. The proxy service (which is typically exposed to all users) allows connections to the internal PostgreSQL database of the appliance. By connec…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2019-19015
|
2024-11-21 13:33 |
2019-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224153
|
7.8 |
HIGH
Local
|
titanhq
|
webtitan
|
An issue was discovered in TitanHQ WebTitan before 5.18. It has a sudoers file that enables low-privilege users to execute a vast number of commands as root, including mv, chown, and chmod. This can …
|
CWE-269
Improper Privilege Management
|
CVE-2019-19014
|
2024-11-21 13:33 |
2019-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224154
|
9.8 |
CRITICAL
Network
|
rabbitmq-c_project fedoraproject canonical debian
|
rabbitmq-c fedora ubuntu_linux debian_linux
|
An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corruption in the handling of CONNECTION_STATE_HEADER. A …
|
CWE-787
Out-of-bounds Write
|
CVE-2019-18609
|
2024-11-21 13:33 |
2019-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224155
|
7.5 |
HIGH
Network
|
alliedtelesis
|
at-gs950\/8_firmware
|
A Directory Traversal in the Web interface of the Allied Telesis AT-GS950/8 until Firmware AT-S107 V.1.1.3 [1.00.047] allows unauthenticated attackers to read arbitrary system files via a GET request…
|
CWE-22
Path Traversal
|
CVE-2019-18922
|
2024-11-21 13:33 |
2019-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224156
|
4.7 |
MEDIUM
Local
|
linux redhat canonical fedoraproject opensuse
|
linux_kernel enterprise_linux ubuntu_linux fedora leap
|
The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs, aka CID-39e72bf96f58. This is related to arch/powerpc/…
|
CWE-200
Information Exposure
|
CVE-2019-18660
|
2024-11-21 13:33 |
2019-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224157
|
7.5 |
HIGH
Network
|
squid-cache canonical debian fedoraproject
|
squid ubuntu_linux debian_linux fedora
|
An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens c…
|
CWE-200
Information Exposure
|
CVE-2019-18679
|
2024-11-21 13:33 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224158
|
5.3 |
MEDIUM
Network
|
squid-cache canonical debian fedoraproject
|
squid ubuntu_linux debian_linux fedora
|
An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend software to a Squid instance that splits the HTTP Request pipeline differently.…
|
CWE-444
HTTP Request Smuggling
|
CVE-2019-18678
|
2024-11-21 13:33 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224159
|
6.1 |
MEDIUM
Network
|
squid-cache canonical fedoraproject
|
squid ubuntu_linux fedora
|
An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to in…
|
CWE-352
Origin Validation Error
|
CVE-2019-18677
|
2024-11-21 13:33 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224160
|
7.5 |
HIGH
Network
|
squid-cache canonical fedoraproject debian
|
squid ubuntu_linux fedora debian_linux
|
An issue was discovered in Squid 3.x and 4.x through 4.8. Due to incorrect input validation, there is a heap-based buffer overflow that can result in Denial of Service to all clients using the proxy.…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-18676
|
2024-11-21 13:33 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|