|
224861
|
9.8 |
CRITICAL
Network
|
skymee petwant
|
petalk_ai_firmware pf-103_firmware
|
The processCommandSetMac() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.
|
CWE-78
OS Command
|
CVE-2019-16737
|
2024-11-21 13:31 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224862
|
9.8 |
CRITICAL
Network
|
skymee petwant
|
petalk_ai_firmware pf-103_firmware
|
A stack-based buffer overflow in processCommandUploadSnapshot in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to cause denial of service or run arb…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-16736
|
2024-11-21 13:31 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224863
|
9.8 |
CRITICAL
Network
|
skymee petwant
|
petalk_ai_firmware pf-103_firmware
|
A stack-based buffer overflow in processCommandUploadLog in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to cause denial of service or run arbitrar…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-16735
|
2024-11-21 13:31 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224864
|
9.8 |
CRITICAL
Network
|
skymee petwant
|
petalk_ai_firmware pf-103_firmware
|
Use of default credentials for the TELNET server in Petwant PF-103 firmware 4.3.2.50 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-16734
|
2024-11-21 13:31 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224865
|
9.8 |
CRITICAL
Network
|
skymee petwant
|
petalk_ai_firmware pf-103_firmware
|
processCommandSetUid() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.
|
CWE-78
OS Command
|
CVE-2019-16733
|
2024-11-21 13:31 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224866
|
8.1 |
HIGH
Network
|
skymee petwant
|
petalk_ai_firmware pf-103_firmware
|
Unencrypted HTTP communications for firmware upgrades in Petalk AI and PF-103 allow man-in-the-middle attackers to run arbitrary code as the root user.
|
CWE-347 CWE-319
Improper Verification of Cryptographic Signature Cleartext Transmission of Sensitive Information
|
CVE-2019-16732
|
2024-11-21 13:31 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224867
|
7.5 |
HIGH
Network
|
skymee petwant
|
petalk_ai_firmware pf-103_firmware
|
The udpServerSys service in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to initiate firmware upgrades and alter device settings.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-16731
|
2024-11-21 13:31 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224868
|
9.8 |
CRITICAL
Network
|
skymee petwant
|
petalk_ai_firmware pf-103_firmware
|
processCommandUpgrade() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.
|
CWE-78
OS Command
|
CVE-2019-16730
|
2024-11-21 13:31 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224869
|
7.5 |
HIGH
Network
|
egain
|
mail
|
The eGain Web Email API 11+ allows spoofed messages because the fromName and message fields (to /system/ws/v11/ss/email) are mishandled, as demonstrated by fromName header injection with a %0a or %0d…
|
CWE-74
Injection
|
CVE-2019-17123
|
2024-11-21 13:31 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224870
|
9.8 |
CRITICAL
Network
|
phpfastcache
|
phpfastcache
|
In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-16774
|
2024-11-21 13:31 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|