|
219301
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was addressed in epan/dissectors/packet-enip.c by changing the memory-management approach so that a use-after-free is avoided.
|
CWE-416
Use After Free
|
CVE-2019-5721
|
2024-11-21 13:45 |
2019-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219302
|
5.5 |
MEDIUM
Local
|
wireshark debian
|
wireshark debian_linux
|
In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the ISAKMP dissector could crash. This was addressed in epan/dissectors/packet-isakmp.c by properly handling the case of a missing decryption data blo…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-5719
|
2024-11-21 13:45 |
2019-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219303
|
5.5 |
MEDIUM
Local
|
wireshark debian
|
wireshark debian_linux
|
In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the RTSE dissector and other ASN.1 dissectors could crash. This was addressed in epan/charsets.c by adding a get_t61_string length check.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-5718
|
2024-11-21 13:45 |
2019-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219304
|
5.5 |
MEDIUM
Local
|
wireshark debian
|
wireshark debian_linux
|
In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the P_MUL dissector could crash. This was addressed in epan/dissectors/packet-p_mul.c by rejecting the invalid sequence number of zero.
|
CWE-20
Improper Input Validation
|
CVE-2019-5717
|
2024-11-21 13:45 |
2019-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219305
|
5.5 |
MEDIUM
Local
|
wireshark debian
|
wireshark debian_linux
|
In Wireshark 2.6.0 to 2.6.5, the 6LoWPAN dissector could crash. This was addressed in epan/dissectors/packet-6lowpan.c by avoiding use of a TVB before its creation.
|
CWE-20
Improper Input Validation
|
CVE-2019-5716
|
2024-11-21 13:45 |
2019-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219306
|
9.8 |
CRITICAL
Network
|
frontaccounting
|
frontaccounting
|
includes/db/class.reflines_db.inc in FrontAccounting 2.4.6 contains a SQL Injection vulnerability in the reference field that can allow the attacker to grab the entire database of the application via…
|
CWE-89
SQL Injection
|
CVE-2019-5720
|
2024-11-21 13:45 |
2019-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219307
|
5.5 |
MEDIUM
Local
|
linux netapp
|
linux_kernel element_software_management_node active_iq_performance_analytics_services
|
The mincore() implementation in mm/mincore.c in the Linux kernel through 4.19.13 allowed local attackers to observe page cache access patterns of other processes on the same system, potentially allow…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-5489
|
2024-11-21 13:45 |
2019-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219308
|
7.5 |
HIGH
Network
|
earclink
|
espcms-p8
|
EARCLINK ESPCMS-P8 has SQL injection in the install_pack/index.php?ac=Member&at=verifyAccount verify_key parameter. install_pack/espcms_public/espcms_db.php may allow retrieving sensitive information…
|
CWE-89
SQL Injection
|
CVE-2019-5488
|
2024-11-21 13:45 |
2019-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219309
|
6.5 |
MEDIUM
Network
|
arubanetworks siemens
|
arubaos scalance_w1750d_firmware
|
A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba Operating System Software version(s): 6.x.x.x: all versions, 8.x.x.x: all versions prior to 8.8.0.0. Aruba has release…
|
CWE-352
Origin Validation Error
|
CVE-2019-5318
|
2024-11-21 13:44 |
2021-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219310
|
7.1 |
HIGH
Network
|
ibm netapp
|
cognos_analytics oncommand_insight
|
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive info…
|
CWE-611
XXE
|
CVE-2019-4730
|
2024-11-21 13:44 |
2021-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|