|
218981
|
5.9 |
MEDIUM
Network
|
huawei
|
ar120-s_firmware ar1200_firmware ar1200-s_firmware ar150_firmware ar150-s_firmware ar160_firmware ar200_firmware ar200-s_firmware ar2200_firmware ar2200-s_firmware ar320…
|
Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated attacker has to intercept specific packets between two devices, modify the packets…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-5291
|
2024-11-21 13:44 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218982
|
6.5 |
MEDIUM
Network
|
huawei
|
s5700_firmware s6700_firmware
|
Huawei S5700 and S6700 have a DoS security vulnerability. Attackers with certain permissions perform specific operations on affected devices. Because the pointer in the program is not processed prope…
|
NVD-CWE-noinfo
|
CVE-2019-5290
|
2024-11-21 13:44 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218983
|
5.5 |
MEDIUM
Local
|
huawei
|
honor_v10_firmware p30_firmware enjoy_7s_firmware mate_20_firmware honor_9_lite_firmware honor_9i_firmware m6_firmware p30_pro_firmware honor_20s_firmware
|
There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficiently validate certain pathnames from the application. An attacker could trick the user into installi…
|
CWE-22
Path Traversal
|
CVE-2019-5251
|
2024-11-21 13:44 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218984
|
7.8 |
HIGH
Local
|
huawei
|
mate_20_pro_firmware
|
Mate 20 Pro smartphones with versions earlier than 9.1.0.135(C00E133R3P1) have an improper authorization vulnerability. The software does not properly restrict certain operation of certain privilege,…
|
CWE-269
Improper Privilege Management
|
CVE-2019-5250
|
2024-11-21 13:44 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218985
|
7.4 |
HIGH
Adjacent
|
huawei
|
cloudengine_12800_firmware
|
CloudEngine 12800 has a DoS vulnerability. An attacker of a neighboring device sends a large number of specific packets. As a result, a memory leak occurs after the device uses the specific packet. A…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-5248
|
2024-11-21 13:44 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218986
|
8.8 |
HIGH
Network
|
kakadusoftware
|
kakadu_software
|
An exploitable heap underflow vulnerability exists in the derive_taps_and_gains function in kdu_v7ar.dll of Kakadu Software SDK 7.10.2. A specially crafted jp2 file can cause a heap overflow, which c…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-5144
|
2024-11-21 13:44 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218987
|
6.5 |
MEDIUM
Adjacent
|
w1.fi
|
hostapd
|
An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for hostapd 2.6 connected clients with valid 802.11w sessions. By simulating an incomplete new association…
|
CWE-346
Origin Validation Error
|
CVE-2019-5062
|
2024-11-21 13:44 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218988
|
6.5 |
MEDIUM
Adjacent
|
w1.fi
|
hostapd
|
An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAPP location updates for stations, before the required authentication process has…
|
CWE-287
Improper Authentication
|
CVE-2019-5061
|
2024-11-21 13:44 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218989
|
8.8 |
HIGH
Network
|
leadtools
|
leadtools
|
An exploitable heap overflow vulnerability exists in the JPEG2000 parsing functionality of LEADTOOLS 20.0.2019.3.15. A specially crafted J2K image file can cause an out of bounds write of a null byte…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-5154
|
2024-11-21 13:44 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218990
|
9.8 |
CRITICAL
Network
|
leadtools
|
leadtools
|
An exploitable code execution vulnerability exists in the DICOM network response functionality of LEADTOOLS libltdic.so version 20.0.2019.3.15. A specially crafted packet can cause an integer overflo…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2019-5093
|
2024-11-21 13:44 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|