|
224081
|
6.6 |
MEDIUM
Physics
|
barco
|
clickshare_button_r9861500d01_firmware
|
Barco ClickShare Button R9861500D01 devices before 1.10.0.13 have Missing Support for Integrity Check. The ClickShare Button does not verify the integrity of the mutable content on the UBIFS partitio…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-18824
|
2024-11-21 13:33 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224082
|
6.8 |
MEDIUM
Physics
|
dell
|
xps_7390_firmware
|
Settings for the Dell XPS 13 2-in-1 (7390) BIOS versions prior to 1.1.3 contain a configuration vulnerability. The BIOS configuration for the "Enable Thunderbolt (and PCIe behind TBT) pre-boot module…
|
NVD-CWE-Other
|
CVE-2019-18579
|
2024-11-21 13:33 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224083
|
5.3 |
MEDIUM
Network
|
barco
|
clickshare_cs-100_firmware clickshare_cse-200_firmware clickshare_cse-200\+_firmware clickshare_cse-800_firmware
|
Barco ClickShare Button R9861500D01 devices before 1.9.0 allow Information Exposure. The encrypted ClickShare Button firmware contains the private key of a test device-certificate.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-18831
|
2024-11-21 13:33 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224084
|
9.8 |
CRITICAL
Network
|
barco
|
clickshare_cs-100_firmware clickshare_cse-200_firmware clickshare_cse-200\+_firmware clickshare_cse-800_firmware
|
Barco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection. The embedded 'dongle_bridge' program used to expose the functionalities of the ClickShare Button to a USB host, is…
|
CWE-78
OS Command
|
CVE-2019-18830
|
2024-11-21 13:33 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224085
|
6.8 |
MEDIUM
Physics
|
barco
|
clickshare_cs-100_firmware clickshare_cse-200_firmware clickshare_cse-200\+_firmware clickshare_cse-800_firmware
|
Barco ClickShare Button R9861500D01 devices before 1.9.0 have Insufficiently Protected Credentials. The root account (present for access via debug interfaces, which are by default not enabled on prod…
|
CWE-521
Weak Password Requirements
|
CVE-2019-18828
|
2024-11-21 13:33 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224086
|
5.9 |
MEDIUM
Network
|
barco
|
clickshare_cs-100_firmware clickshare_cse-200_firmware clickshare_cse-200\+_firmware clickshare_cse-800_firmware
|
On Barco ClickShare Button R9861500D01 devices (before firmware version 1.9.0) JTAG access is disabled after ROM code execution. This means that JTAG access is possible when the system is running cod…
|
CWE-362 CWE-285
Race Condition Improper Authorization
|
CVE-2019-18827
|
2024-11-21 13:33 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224087
|
9.8 |
CRITICAL
Network
|
barco
|
clickshare_cs-100_firmware clickshare_cse-200_firmware clickshare_cse-200\+_firmware clickshare_cse-800_firmware
|
Barco ClickShare Button R9861500D01 devices before 1.9.0 have Improper Following of a Certificate's Chain of Trust. The embedded 'dongle_bridge' program used to expose the functionalities of the Clic…
|
CWE-295
Improper Certificate Validation
|
CVE-2019-18826
|
2024-11-21 13:33 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224088
|
7.5 |
HIGH
Network
|
envoyproxy
|
envoy
|
An issue was discovered in Envoy 1.12.0. Upon receipt of a malformed HTTP request without a Host header, it sends an internally generated "Invalid request" response. This internally generated respons…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-18838
|
2024-11-21 13:33 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224089
|
9.8 |
CRITICAL
Network
|
envoyproxy
|
envoy
|
An issue was discovered in Envoy 1.12.0. An untrusted remote client may send an HTTP header (such as Host) with whitespace after the header content. Envoy will treat "header-value " as a different st…
|
NVD-CWE-noinfo
|
CVE-2019-18802
|
2024-11-21 13:33 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224090
|
9.8 |
CRITICAL
Network
|
envoyproxy
|
envoy
|
An issue was discovered in Envoy 1.12.0. An untrusted remote client may send HTTP/2 requests that write to the heap outside of the request buffers when the upstream is HTTP/1. This may be used to cor…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-18801
|
2024-11-21 13:33 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|