|
225391
|
6.1 |
MEDIUM
Network
|
usriot
|
usr-wifi232-s_firmware usr-wifi232-t_firmware usr-wifi232-g2_firmware usr-wifi232-h_firmware
|
A cross-site scripting (XSS) vulnerability in the configuration web interface of the Jinan USR IOT USR-WIFI232-S/T/G2/H Low Power WiFi Module with web version 1.2.2 allows attackers to leak credentia…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18842
|
2024-11-21 13:33 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225392
|
7.5 |
HIGH
Network
|
oisf debian
|
suricata debian_linux
|
An issue was discovered in Suricata 5.0.0. It was possible to bypass/evade any tcp based signature by faking a closed TCP session using an evil server. After the TCP SYN packet, it is possible to inj…
|
NVD-CWE-noinfo
|
CVE-2019-18625
|
2024-11-21 13:33 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225393
|
9.1 |
CRITICAL
Network
|
oisf debian
|
suricata debian_linux
|
An issue was discovered in Suricata 5.0.0. It is possible to bypass/evade any tcp based signature by overlapping a TCP segment with a fake FIN packet. The fake FIN packet is injected just before the …
|
CWE-436
Interpretation Conflict
|
CVE-2019-18792
|
2024-11-21 13:33 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225394
|
8.8 |
HIGH
Local
|
avira
|
free_antivirus
|
Avira Free Antivirus 15.0.1907.1514 is prone to a local privilege escalation through the execution of kernel code from a restricted user.
|
NVD-CWE-noinfo
|
CVE-2019-18568
|
2024-11-21 13:33 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225395
|
5.5 |
MEDIUM
Local
|
virglrenderer_project redhat opensuse debian
|
virglrenderer enterprise_linux leap debian_linux
|
A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_RES…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-18391
|
2024-11-21 13:33 |
2019-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225396
|
7.1 |
HIGH
Local
|
virglrenderer_project redhat opensuse debian
|
virglrenderer enterprise_linux leap debian_linux
|
An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_BLIT commands.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-18390
|
2024-11-21 13:33 |
2019-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225397
|
7.8 |
HIGH
Local
|
virglrenderer_project redhat opensuse debian
|
virglrenderer enterprise_linux leap debian_linux
|
A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service, or QEMU guest-to-…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-18389
|
2024-11-21 13:33 |
2019-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225398
|
5.5 |
MEDIUM
Local
|
virglrenderer_project opensuse debian
|
virglrenderer leap debian_linux
|
A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via malformed commands.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-18388
|
2024-11-21 13:33 |
2019-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225399
|
6.1 |
MEDIUM
Network
|
lansweeper
|
lansweeper
|
The web console in Lansweeper 7.2.105.2 has XSS via the URL path. Product vulnerability has been fixed and disclosed within changelog as of 02 Dec 2019.
|
CWE-79
Cross-site Scripting
|
CVE-2019-18955
|
2024-11-21 13:33 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225400
|
4.9 |
MEDIUM
Network
|
arista
|
cloudvision_portal
|
In CloudVision Portal (CVP) for all releases in the 2018.2 Train, under certain conditions, the application logs user passwords in plain text for certain API calls, potentially leading to user passwo…
|
CWE-312 CWE-522
Cleartext Storage of Sensitive Information Insufficiently Protected Credentials
|
CVE-2019-18615
|
2024-11-21 13:33 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|