|
223501
|
6.5 |
MEDIUM
Network
|
un4seen
|
bass
|
The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Denial of Service vulnerability (infinite loop) via a crafted .mp3 file. This weakness could allow attackers to consume…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-18796
|
2024-11-21 13:33 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223502
|
6.5 |
MEDIUM
Network
|
un4seen
|
bass
|
The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile out of bounds read vulnerability via a crafted .wav file. An attacker can exploit this issues to gain access to sensiti…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-18795
|
2024-11-21 13:33 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223503
|
6.5 |
MEDIUM
Network
|
un4seen
|
bass
|
The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Use after Free vulnerability via a crafted .ogg file. An attacker can exploit this to gain access to sensitive informat…
|
CWE-416
Use After Free
|
CVE-2019-18794
|
2024-11-21 13:33 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223504
|
5.4 |
MEDIUM
Adjacent
|
qualcomm
|
atheros_ar9132_firmware atheros_ar9283_firmware atheros_ar9285_firmware
|
A partial authentication bypass vulnerability exists on Atheros AR9132 3.60(AMX.8), AR9283 1.85, and AR9285 1.0.0.12NA devices. The vulnerability allows sending an unencrypted data frame to a WPA2-pr…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2019-18991
|
2024-11-21 13:33 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223505
|
5.4 |
MEDIUM
Adjacent
|
realtek
|
rtl8812ar_firmware rtl8196d_firmware rtl8192er_firmware rtl8881an_firmware
|
A partial authentication bypass vulnerability exists on Realtek RTL8812AR 1.21WW, RTL8196D 1.0.0, RTL8192ER 2.10, and RTL8881AN 1.09 devices. The vulnerability allows sending an unencrypted data fram…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2019-18990
|
2024-11-21 13:33 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223506
|
5.4 |
MEDIUM
Adjacent
|
mediatek
|
mt7620n_firmware
|
A partial authentication bypass vulnerability exists on Mediatek MT7620N 1.06 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is r…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2019-18989
|
2024-11-21 13:33 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223507
|
9.8 |
CRITICAL
Network
|
akamai
|
enterprise_application_access
|
Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1.
|
CWE-295
Improper Certificate Validation
|
CVE-2019-18847
|
2024-11-21 13:33 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223508
|
6.1 |
MEDIUM
Network
|
woocommerce
|
subscriptions
|
Persistent XSS in the WooCommerce Subscriptions plugin before 2.6.3 for WordPress allows remote attackers to execute arbitrary JavaScript because Billing Details are mishandled in WCS_Admin_Post_Type…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18834
|
2024-11-21 13:33 |
2020-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223509
|
7.8 |
HIGH
Local
|
synaptics lenovo hp
|
vfs75xx_firmware thinkpad_25_firmware thankpad_a475_firmware thankpad_a485_firmware thinkpad_e480_firmware thinkpad_e580_firmware thinkpad_e485_firmware thinkpad_e585_firmware
|
Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (…
|
CWE-763
Release of Invalid Pointer or Reference
|
CVE-2019-18619
|
2024-11-21 13:33 |
2020-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223510
|
6.0 |
MEDIUM
Local
|
synaptics lenovo hp
|
vfs75xx_firmware thinkpad_25_firmware thankpad_a475_firmware thankpad_a485_firmware thinkpad_e480_firmware thinkpad_e580_firmware thinkpad_e485_firmware thinkpad_e585_firmware
|
Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attack…
|
NVD-CWE-noinfo
|
CVE-2019-18618
|
2024-11-21 13:33 |
2020-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|