| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-15490 | Hig | 0.46 | 7.1 | 0.01 | Jan 2, 2019 | An issue was discovered in ExpressVPN on Windows. The Xvpnd.exe process (which runs as a service with SYSTEM privileges) listens on TCP port 2015, which is used as an RPC interface for communication with the client side of the ExpressVPN application. A JSON-RPC protocol over… | ||
| CVE-2019-3574 | Hig | 0.51 | 7.8 | 0.01 | Jan 2, 2019 | In libsixel v1.8.2, there is a heap-based buffer over-read in the function load_jpeg() in the file loader.c, as demonstrated by img2sixel. | ||
| CVE-2018-20658 | Hig | 0.52 | 7.5 | 0.08 | Jan 2, 2019 | The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon crash) via a crafted XRMD command. | ||
| CVE-2018-5197 | Hig | 0.51 | 7.8 | 0.01 | Jan 2, 2019 | A vulnerability in the ExtCommon.dll user extension module version 9.2, 9.2.1, 9.2.2 of Xplatform ActiveX could allow attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command parameters. An crafted malicious parameters… | ||
| CVE-2018-20657 | Hig | 0.49 | 7.5 | 0.04 | Jan 2, 2019 | The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698. | ||
| CVE-2018-17188 | Hig | 0.47 | 7.2 | 0.03 | Jan 2, 2019 | Prior to CouchDB version 2.3.0, CouchDB allowed for runtime-configuration of key components of the database. In some cases, this lead to vulnerabilities where CouchDB admin users could access the underlying operating system as the CouchDB user. Together with other… | ||
| CVE-2019-3500 | Hig | 0.51 | 7.8 | 0.00 | Jan 2, 2019 | aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and password in a file, which might allow local users to obtain sensitive information by reading this file. | ||
| CVE-2019-3494 | Hig | 0.49 | 7.5 | 0.01 | Jan 1, 2019 | Simply-Blog through 2019-01-01 has SQL Injection via the admin/deleteCategories.php delete parameter. | ||
| CVE-2018-6347 | Hig | 0.00 | 7.5 | 0.01 | Dec 31, 2018 | An issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affects Proxygen prior to v2018.12.31.00. | ||
| CVE-2018-6346 | Hig | 0.00 | 7.5 | 0.01 | Dec 31, 2018 | A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 priority settings (specifically a circular dependency). This affects Proxygen prior to v2018.12.31.00. | ||
| CVE-2018-6344 | Hig | 0.49 | 7.5 | 0.02 | Dec 31, 2018 | A heap corruption in WhatsApp can be caused by a malformed RTP packet being sent after a call is established. The vulnerability can be used to cause denial of service. It affects WhatsApp for Android prior to v2.18.293, WhatsApp for iOS prior to v2.18.93, and WhatsApp for… | ||
| CVE-2018-6343 | Hig | 0.00 | 7.5 | 0.01 | Dec 31, 2018 | Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue when parsing a Certificate/CertificateRequest HTTP2 Frame over a fizz (TLS 1.3) transport. This issue affects Proxygen releases starting from… | ||
| CVE-2018-6340 | Hig | 0.00 | 8.1 | 0.01 | Dec 31, 2018 | The Memcache::getextendedstats function can be used to trigger an out-of-bounds read. Exploiting this issue requires control over memcached server hostnames and/or ports. This affects all supported versions of HHVM (3.30 and 3.27.4 and below). | ||
| CVE-2018-6337 | Hig | 0.00 | 7.5 | 0.02 | Dec 31, 2018 | folly::secureRandom will re-use a buffer between parent and child processes when fork() is called. That will result in multiple forked children producing repeat (or similar) results. This affects HHVM 3.26 prior to 3.26.3 and the folly library between v2017.12.11.00 and… | ||
| CVE-2018-6336 | Hig | 0.51 | 7.8 | 0.00 | Dec 31, 2018 | An issue was discovered in osquery. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by Apple, but the… | ||
| CVE-2018-6335 | Hig | 0.00 | 7.5 | 0.01 | Dec 31, 2018 | A Malformed h2 frame can cause 'std::out_of_range' exception when parsing priority meta data. This behavior can lead to denial-of-service. This affects all supported versions of HHVM (3.25.2, 3.24.6, and 3.21.10 and below) when using the proxygen server to handle HTTP2 requests. | ||
| CVE-2018-18601 | Hig | 0.53 | 8.1 | 0.01 | Dec 31, 2018 | The TK_set_deviceModel_req_handle function in the cloud communication component in Guardzilla GZ621W devices with firmware 0.5.1.4 has a Buffer Overflow. | ||
| CVE-2018-18600 | Hig | 0.53 | 8.1 | 0.02 | Dec 31, 2018 | The remote upgrade feature in Guardzilla GZ180 devices allow command injection via a crafted new firmware version parameter. | ||
| CVE-2018-20618 | Hig | 0.57 | 8.8 | 0.01 | Dec 31, 2018 | ok-file-formats through 2018-10-16 has a heap-based buffer over-read in the ok_mo_decode2 function in ok_mo.c. | ||
| CVE-2018-20617 | Hig | 0.57 | 8.8 | 0.01 | Dec 31, 2018 | ok-file-formats through 2018-10-16 has a heap-based buffer overflow in the ok_csv_decode2 function in ok_csv.c. | ||
| CVE-2018-20616 | Hig | 0.57 | 8.8 | 0.01 | Dec 31, 2018 | ok-file-formats through 2018-10-16 has a heap-based buffer overflow in the ok_wav_decode_ms_adpcm_data function in ok_wav.c. | ||
| CVE-2018-20614 | Hig | 0.49 | 7.5 | 0.01 | Dec 30, 2018 | public\install\install.php in CIM 0.9.3 allows remote attackers to reload the product via the public/install/#/step3 URI. | ||
| CVE-2018-20613 | Hig | 0.57 | 8.8 | 0.00 | Dec 30, 2018 | TEMMOKU T1.09 Beta allows admin/user/add CSRF. | ||
| CVE-2018-20612 | Hig | 0.57 | 8.8 | 0.00 | Dec 30, 2018 | UWA 2.3.11 allows index.php?g=admin&c=admin&a=add_admin_do CSRF. | ||
| CVE-2018-20608 | Hig | 0.50 | 7.5 | 0.12 | Dec 30, 2018 | imcat 4.4 allows remote attackers to read phpinfo output via the root/tools/adbug/binfo.php?phpinfo1 URI. | ||
| CVE-2018-20606 | Hig | 0.49 | 7.5 | 0.03 | Dec 30, 2018 | imcat 4.4 allows full path disclosure via a dev.php?tools-ipaddr&api=Pcoln&uip= URI. | ||
| CVE-2018-20603 | — | Hig | 0.57 | 8.8 | 0.01 | Dec 30, 2018 | Lei Feng TV CMS (aka LFCMS) 3.8.6 allows admin.php?s=/Member/add.html CSRF. | |
| CVE-2018-20602 | Hig | 0.49 | 7.5 | 0.01 | Dec 30, 2018 | Lei Feng TV CMS (aka LFCMS) 3.8.6 allows full path disclosure via the /install.php?s=/1 URI. | ||
| CVE-2018-20599 | Hig | 0.57 | 8.8 | 0.02 | Dec 30, 2018 | UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileedit action. | ||
| CVE-2018-20598 | Hig | 0.57 | 8.8 | 0.01 | Dec 30, 2018 | UCMS 1.4.7 has ?do=user_addpost CSRF. | ||
| CVE-2018-20595 | Hig | 0.50 | 8.8 | 0.01 | Dec 30, 2018 | A CSRF issue was discovered in web/authorization/oauth2/controller/OAuth2ClientController.java in hsweb 3.0.4 because the state parameter in the request is not compared with the state parameter in the session after user authentication is successful. | ||
| CVE-2018-15007 | Hig | 0.51 | 7.8 | 0.00 | Dec 28, 2018 | The Sky Elite 6.0L+ Android device with a build fingerprint of SKY/x6069_trx_l601_sky/x6069_trx_l601_sky:6.0/MRA58K/1482897127:user/release-keys contains a pre-installed platform app with a package name of com.fw.upgrade.sysoper (versionCode=238, versionName=2.3.8) that contains… | ||
| CVE-2018-15005 | Hig | 0.46 | 7.1 | 0.00 | Dec 28, 2018 | The ZTE ZMAX Champ Android device with a build fingerprint of ZTE/Z917VL/fortune:6.0.1/MMB29M/20170327.120922:user/release-keys contains a pre-installed platform app with a package name of com.zte.zdm.sdm (versionCode=31, versionName=V5.0.3) that contains an exported broadcast… | ||
| CVE-2018-14988 | Hig | 0.49 | 7.5 | 0.01 | Dec 28, 2018 | The MXQ TV Box 4.4.2 Android device with a build fingerprint of MBX/m201_N/m201_N:4.4.2/KOT49H/20160106:user/test-keys contains the Android framework with a package name of android (versionCode=19, versionName=4.4.2-20170213) that contains an exported broadcast receiver… | ||
| CVE-2018-14987 | Hig | 0.46 | 7.1 | 0.00 | Dec 28, 2018 | The MXQ TV Box 4.4.2 Android device with a build fingerprint of MBX/m201_N/m201_N:4.4.2/KOT49H/20160106:user/test-keys contains the Android framework with a package name of android (versionCode=19, versionName=4.4.2-20170213) that dynamically registers a broadcast receiver app… | ||
| CVE-2018-14986 | Hig | 0.49 | 7.5 | 0.01 | Dec 28, 2018 | The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed app with a package name of com.android.messaging (versionCode=1000110, versionName=1.0.001, (android.20170630.092853-0))… | ||
| CVE-2018-14985 | Hig | 0.46 | 7.1 | 0.00 | Dec 28, 2018 | The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed platform app with a package name of com.android.settings (versionCode=23, versionName=6.0-android.20170630.092853) that… | ||
| CVE-2018-14984 | Hig | 0.49 | 7.5 | 0.01 | Dec 28, 2018 | The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed app with a package name of com.android.messaging (versionCode=1000110, versionName=1.0.001, (android.20170630.092853-0))… | ||
| CVE-2018-20579 | Hig | 0.46 | 7.1 | 0.00 | Dec 28, 2018 | Contiki-NG before 4.2 has a stack-based buffer overflow in the push function in os/lib/json/jsonparse.c that allows an out-of-bounds write of an '{' or '[' character. | ||
| CVE-2018-20578 | Hig | 0.49 | 7.5 | 0.02 | Dec 28, 2018 | An issue was discovered in NuttX before 7.27. The function netlib_parsehttpurl() in apps/netutils/netlib/netlib_parsehttpurl.c mishandles URLs longer than hostlen bytes (in the webclient, this is set by default to 40), leading to an Infinite Loop. The attack vector is the… | ||
| CVE-2018-20575 | Hig | 0.49 | 7.5 | 0.01 | Dec 28, 2018 | Orange Livebox 00.96.320S devices have an undocumented /system_firmwarel.stm URI for manual firmware update. This is related to Firmware 01.11.2017-11:43:44, Boot v0.70.03, Modem 5.4.1.10.1.1A, Hardware 02, and Arcadyan ARV7519RW22-A-L T VR9 1.2. | ||
| CVE-2018-18696 | Hig | 0.57 | 8.8 | 0.01 | Dec 28, 2018 | main.aspx in Microstrategy Analytics 10.4.0026.0049 and earlier has CSRF. NOTE: The vendor claims that documentation for preventing a CSRF attack has been provided (https://community.microstrategy.com/s/article/KB37643-New-security-feature-introduced-in-MicroStrategy-Web-9-0?lang… | ||
| CVE-2018-18667 | Hig | 0.49 | 7.5 | 0.01 | Dec 28, 2018 | The mintToken function of Pylon (PYLNT) aka PylonToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value, a related issue to CVE-2018-11812. | ||
| CVE-2018-18666 | Hig | 0.49 | 7.5 | 0.01 | Dec 28, 2018 | The mintToken function of SwftCoin (SWFTC) aka SwftCoin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | ||
| CVE-2018-18665 | Hig | 0.49 | 7.5 | 0.01 | Dec 28, 2018 | The mintToken function of Nexxus (NXX) aka NexxusToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | ||
| CVE-2018-20571 | Hig | 0.49 | 7.5 | 0.01 | Dec 28, 2018 | DamiCMS 6.0.1 allows remote attackers to read arbitrary files via a crafted admin.php?s=Tpl/Add/id request, as demonstrated by admin.php?s=Tpl/Add/id/.\Public\Config\config.ini.php to read the global configuration file. | ||
| CVE-2018-20553 | Hig | 0.00 | 7.8 | 0.01 | Dec 28, 2018 | Tcpreplay before 4.3.1 has a heap-based buffer over-read in get_l2len in common/get.c. | ||
| CVE-2018-20552 | Hig | 0.00 | 7.8 | 0.01 | Dec 28, 2018 | Tcpreplay before 4.3.1 has a heap-based buffer over-read in packet2tree in tree.c. | ||
| CVE-2018-20549 | Hig | 0.57 | 8.8 | 0.02 | Dec 28, 2018 | There is an illegal WRITE memory access at caca/file.c (function caca_file_read) in libcaca 0.99.beta19. | ||
| CVE-2018-20548 | Hig | 0.57 | 8.8 | 0.02 | Dec 28, 2018 | There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 1bpp data. |
- risk 0.46cvss 7.1epss 0.01
An issue was discovered in ExpressVPN on Windows. The Xvpnd.exe process (which runs as a service with SYSTEM privileges) listens on TCP port 2015, which is used as an RPC interface for communication with the client side of the ExpressVPN application. A JSON-RPC protocol over…
- risk 0.51cvss 7.8epss 0.01
In libsixel v1.8.2, there is a heap-based buffer over-read in the function load_jpeg() in the file loader.c, as demonstrated by img2sixel.
- risk 0.52cvss 7.5epss 0.08
The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon crash) via a crafted XRMD command.
- risk 0.51cvss 7.8epss 0.01
A vulnerability in the ExtCommon.dll user extension module version 9.2, 9.2.1, 9.2.2 of Xplatform ActiveX could allow attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command parameters. An crafted malicious parameters…
- risk 0.49cvss 7.5epss 0.04
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698.
- risk 0.47cvss 7.2epss 0.03
Prior to CouchDB version 2.3.0, CouchDB allowed for runtime-configuration of key components of the database. In some cases, this lead to vulnerabilities where CouchDB admin users could access the underlying operating system as the CouchDB user. Together with other…
- risk 0.51cvss 7.8epss 0.00
aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and password in a file, which might allow local users to obtain sensitive information by reading this file.
- risk 0.49cvss 7.5epss 0.01
Simply-Blog through 2019-01-01 has SQL Injection via the admin/deleteCategories.php delete parameter.
- risk 0.00cvss 7.5epss 0.01
An issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affects Proxygen prior to v2018.12.31.00.
- risk 0.00cvss 7.5epss 0.01
A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 priority settings (specifically a circular dependency). This affects Proxygen prior to v2018.12.31.00.
- risk 0.49cvss 7.5epss 0.02
A heap corruption in WhatsApp can be caused by a malformed RTP packet being sent after a call is established. The vulnerability can be used to cause denial of service. It affects WhatsApp for Android prior to v2.18.293, WhatsApp for iOS prior to v2.18.93, and WhatsApp for…
- risk 0.00cvss 7.5epss 0.01
Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue when parsing a Certificate/CertificateRequest HTTP2 Frame over a fizz (TLS 1.3) transport. This issue affects Proxygen releases starting from…
- risk 0.00cvss 8.1epss 0.01
The Memcache::getextendedstats function can be used to trigger an out-of-bounds read. Exploiting this issue requires control over memcached server hostnames and/or ports. This affects all supported versions of HHVM (3.30 and 3.27.4 and below).
- risk 0.00cvss 7.5epss 0.02
folly::secureRandom will re-use a buffer between parent and child processes when fork() is called. That will result in multiple forked children producing repeat (or similar) results. This affects HHVM 3.26 prior to 3.26.3 and the folly library between v2017.12.11.00 and…
- risk 0.51cvss 7.8epss 0.00
An issue was discovered in osquery. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by Apple, but the…
- risk 0.00cvss 7.5epss 0.01
A Malformed h2 frame can cause 'std::out_of_range' exception when parsing priority meta data. This behavior can lead to denial-of-service. This affects all supported versions of HHVM (3.25.2, 3.24.6, and 3.21.10 and below) when using the proxygen server to handle HTTP2 requests.
- risk 0.53cvss 8.1epss 0.01
The TK_set_deviceModel_req_handle function in the cloud communication component in Guardzilla GZ621W devices with firmware 0.5.1.4 has a Buffer Overflow.
- risk 0.53cvss 8.1epss 0.02
The remote upgrade feature in Guardzilla GZ180 devices allow command injection via a crafted new firmware version parameter.
- risk 0.57cvss 8.8epss 0.01
ok-file-formats through 2018-10-16 has a heap-based buffer over-read in the ok_mo_decode2 function in ok_mo.c.
- risk 0.57cvss 8.8epss 0.01
ok-file-formats through 2018-10-16 has a heap-based buffer overflow in the ok_csv_decode2 function in ok_csv.c.
- risk 0.57cvss 8.8epss 0.01
ok-file-formats through 2018-10-16 has a heap-based buffer overflow in the ok_wav_decode_ms_adpcm_data function in ok_wav.c.
- risk 0.49cvss 7.5epss 0.01
public\install\install.php in CIM 0.9.3 allows remote attackers to reload the product via the public/install/#/step3 URI.
- risk 0.57cvss 8.8epss 0.00
TEMMOKU T1.09 Beta allows admin/user/add CSRF.
- risk 0.57cvss 8.8epss 0.00
UWA 2.3.11 allows index.php?g=admin&c=admin&a=add_admin_do CSRF.
- risk 0.50cvss 7.5epss 0.12
imcat 4.4 allows remote attackers to read phpinfo output via the root/tools/adbug/binfo.php?phpinfo1 URI.
- risk 0.49cvss 7.5epss 0.03
imcat 4.4 allows full path disclosure via a dev.php?tools-ipaddr&api=Pcoln&uip= URI.
- risk 0.57cvss 8.8epss 0.01
Lei Feng TV CMS (aka LFCMS) 3.8.6 allows admin.php?s=/Member/add.html CSRF.
- risk 0.49cvss 7.5epss 0.01
Lei Feng TV CMS (aka LFCMS) 3.8.6 allows full path disclosure via the /install.php?s=/1 URI.
- risk 0.57cvss 8.8epss 0.02
UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileedit action.
- risk 0.57cvss 8.8epss 0.01
UCMS 1.4.7 has ?do=user_addpost CSRF.
- risk 0.50cvss 8.8epss 0.01
A CSRF issue was discovered in web/authorization/oauth2/controller/OAuth2ClientController.java in hsweb 3.0.4 because the state parameter in the request is not compared with the state parameter in the session after user authentication is successful.
- risk 0.51cvss 7.8epss 0.00
The Sky Elite 6.0L+ Android device with a build fingerprint of SKY/x6069_trx_l601_sky/x6069_trx_l601_sky:6.0/MRA58K/1482897127:user/release-keys contains a pre-installed platform app with a package name of com.fw.upgrade.sysoper (versionCode=238, versionName=2.3.8) that contains…
- risk 0.46cvss 7.1epss 0.00
The ZTE ZMAX Champ Android device with a build fingerprint of ZTE/Z917VL/fortune:6.0.1/MMB29M/20170327.120922:user/release-keys contains a pre-installed platform app with a package name of com.zte.zdm.sdm (versionCode=31, versionName=V5.0.3) that contains an exported broadcast…
- risk 0.49cvss 7.5epss 0.01
The MXQ TV Box 4.4.2 Android device with a build fingerprint of MBX/m201_N/m201_N:4.4.2/KOT49H/20160106:user/test-keys contains the Android framework with a package name of android (versionCode=19, versionName=4.4.2-20170213) that contains an exported broadcast receiver…
- risk 0.46cvss 7.1epss 0.00
The MXQ TV Box 4.4.2 Android device with a build fingerprint of MBX/m201_N/m201_N:4.4.2/KOT49H/20160106:user/test-keys contains the Android framework with a package name of android (versionCode=19, versionName=4.4.2-20170213) that dynamically registers a broadcast receiver app…
- risk 0.49cvss 7.5epss 0.01
The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed app with a package name of com.android.messaging (versionCode=1000110, versionName=1.0.001, (android.20170630.092853-0))…
- risk 0.46cvss 7.1epss 0.00
The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed platform app with a package name of com.android.settings (versionCode=23, versionName=6.0-android.20170630.092853) that…
- risk 0.49cvss 7.5epss 0.01
The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed app with a package name of com.android.messaging (versionCode=1000110, versionName=1.0.001, (android.20170630.092853-0))…
- risk 0.46cvss 7.1epss 0.00
Contiki-NG before 4.2 has a stack-based buffer overflow in the push function in os/lib/json/jsonparse.c that allows an out-of-bounds write of an '{' or '[' character.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in NuttX before 7.27. The function netlib_parsehttpurl() in apps/netutils/netlib/netlib_parsehttpurl.c mishandles URLs longer than hostlen bytes (in the webclient, this is set by default to 40), leading to an Infinite Loop. The attack vector is the…
- risk 0.49cvss 7.5epss 0.01
Orange Livebox 00.96.320S devices have an undocumented /system_firmwarel.stm URI for manual firmware update. This is related to Firmware 01.11.2017-11:43:44, Boot v0.70.03, Modem 5.4.1.10.1.1A, Hardware 02, and Arcadyan ARV7519RW22-A-L T VR9 1.2.
- risk 0.57cvss 8.8epss 0.01
main.aspx in Microstrategy Analytics 10.4.0026.0049 and earlier has CSRF. NOTE: The vendor claims that documentation for preventing a CSRF attack has been provided (https://community.microstrategy.com/s/article/KB37643-New-security-feature-introduced-in-MicroStrategy-Web-9-0?lang…
- risk 0.49cvss 7.5epss 0.01
The mintToken function of Pylon (PYLNT) aka PylonToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value, a related issue to CVE-2018-11812.
- risk 0.49cvss 7.5epss 0.01
The mintToken function of SwftCoin (SWFTC) aka SwftCoin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
- risk 0.49cvss 7.5epss 0.01
The mintToken function of Nexxus (NXX) aka NexxusToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
- risk 0.49cvss 7.5epss 0.01
DamiCMS 6.0.1 allows remote attackers to read arbitrary files via a crafted admin.php?s=Tpl/Add/id request, as demonstrated by admin.php?s=Tpl/Add/id/.\Public\Config\config.ini.php to read the global configuration file.
- risk 0.00cvss 7.8epss 0.01
Tcpreplay before 4.3.1 has a heap-based buffer over-read in get_l2len in common/get.c.
- risk 0.00cvss 7.8epss 0.01
Tcpreplay before 4.3.1 has a heap-based buffer over-read in packet2tree in tree.c.
- risk 0.57cvss 8.8epss 0.02
There is an illegal WRITE memory access at caca/file.c (function caca_file_read) in libcaca 0.99.beta19.
- risk 0.57cvss 8.8epss 0.02
There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 1bpp data.