|
224671
|
7.8 |
HIGH
Local
|
axiosys
|
bento4
|
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in AP4_CencSampleEncryption::DoInspectFields in Core/Ap4CommonEncryption.cpp when called from AP4_Atom::Inspect in Co…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-17529
|
2024-11-21 13:32 |
2019-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224672
|
7.5 |
HIGH
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 1.5.1.0. There is a SEGV in the function AP4_TfhdAtom::SetDefaultSampleSize at Core/Ap4TfhdAtom.h when called from AP4_Processor::ProcessFragments in Core/Ap4Process…
|
NVD-CWE-noinfo
|
CVE-2019-17528
|
2024-11-21 13:32 |
2019-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224673
|
7.5 |
HIGH
Network
|
hydra_project
|
hydra
|
Hydra through 0.1.8 has a NULL pointer dereference and daemon crash when processing POST requests that lack a Content-Length header. read.c, request.c, and util.c contribute to this. The process_head…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-17502
|
2024-11-21 13:32 |
2019-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224674
|
4.8 |
MEDIUM
Network
|
hotarucms
|
hotarucms
|
A stored XSS vulnerability was discovered in Hotaru CMS v1.7.2 via the admin_index.php?page=settings SITE NAME field (aka SITE_NAME), a related issue to CVE-2011-4709.1.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17522
|
2024-11-21 13:32 |
2019-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224675
|
6.5 |
MEDIUM
Network
|
landing-cms_project
|
landing-cms
|
An issue was discovered in Landing-CMS 0.0.6. There is a CSRF vulnerability that can change the admin's password via the password/ URI,
|
CWE-352
Origin Validation Error
|
CVE-2019-17521
|
2024-11-21 13:32 |
2019-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224676
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-846_firmware
|
D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a /HNAP1/ request for SetWizardConfig with shell met…
|
CWE-78
OS Command
|
CVE-2019-17510
|
2024-11-21 13:32 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224677
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-846_firmware
|
D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a /HNAP1/ request for SetMasterWLanSettings with she…
|
CWE-78
OS Command
|
CVE-2019-17509
|
2024-11-21 13:32 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224678
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-859_a3_firmware dir-850l_a_firmware
|
On D-Link DIR-859 A3-1.06 and DIR-850 A1.13 devices, /etc/services/DEVICE.TIME.php allows command injection via the $SERVER variable.
|
CWE-78
OS Command
|
CVE-2019-17508
|
2024-11-21 13:32 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224679
|
7.5 |
HIGH
Network
|
dlink
|
dir-816_a1_firmware
|
An issue was discovered on D-Link DIR-816 A1 1.06 devices. An attacker could access management pages of the router via a client that ignores the 'top.location.href = "/dir_login.asp"' line in a .asp …
|
CWE-20
Improper Input Validation
|
CVE-2019-17507
|
2024-11-21 13:32 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224680
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-868l_b1_firmware dir-817lw_a1_firmware
|
There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the router's username and password (and other informati…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-17506
|
2024-11-21 13:32 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|