• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-9122
D-link, Dir-825 Rev.b, Dir-825 Rev.b Firmware
Dir-825/ac_g1_firmware, Dir-825/ac_g1, Dsl-2875al_firmware, Dsl-2875al, Dsl-2877al_firmware, Dsl-2877al, Dap-1360_revision_f_firmware, Dap-1360_revision_f, Dsl-2680_firmware, Dsl-2680
2020-08-24
N/A
8.8 HIGH
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the ntp_server parameter in an ntp_sync.cgi POST request.
CVE-2019-9121
M2, Motorola
Cx2_firmware, Cx2, M2_firmware, M2, Cx2l_mwr04l_firmware, Cx2l_mwr04l, C1_mwr03_firmware, C1_mwr03, Motorola_firmware, C1_firmware
2020-08-24
N/A
9.8 CRITICAL
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when any HNAP API function triggers a call to the system function with untrusted input from the request body for the SetSmartQoSSettings API function, as demonstrated by shell metacharacters in the smartqos_priority_devices field.
CVE-2019-9120
M2, Motorola
Cx2_firmware, Cx2, M2_firmware, M2, Cx2l_mwr04l_firmware, Cx2l_mwr04l, C1_mwr03_firmware, C1_mwr03, Motorola_firmware, C1_firmware
2019-03-08
N/A
9.8 CRITICAL
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when any HNAP API function triggers a call to the system function with untrusted input from the request body for the SetWLanACLSettings API function, as demonstrated by shell metacharacters in the wl(0).(0)_maclist field.
CVE-2019-9119
M2, Motorola
Cx2_firmware, Cx2, M2_firmware, M2, Cx2l_mwr04l_firmware, Cx2l_mwr04l, C1_mwr03_firmware, C1_mwr03, Motorola_firmware, C1_firmware
2019-03-08
N/A
9.8 CRITICAL
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when any HNAP API function triggers a call to the system function with untrusted input from the request body for the SetStaticRouteSettings API function, as demonstrated by shell metacharacters in the staticroute_list field.
CVE-2019-9118
M2, Motorola
Cx2_firmware, Cx2, M2_firmware, M2, Cx2l_mwr04l_firmware, Cx2l_mwr04l, C1_mwr03_firmware, C1_mwr03, Motorola_firmware, C1_firmware
2019-03-08
N/A
9.8 CRITICAL
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when any HNAP API function triggers a call to the system function with untrusted input from the request body for the SetNTPServerSettings API function, as demonstrated by shell metacharacters in the system_time_timezone field.
CVE-2019-9117
M2, Motorola
Cx2_firmware, Cx2, M2_firmware, M2, Cx2l_mwr04l_firmware, Cx2l_mwr04l, C1_mwr03_firmware, C1_mwr03, Motorola_firmware, C1_firmware
2019-03-08
N/A
9.8 CRITICAL
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when any HNAP API function triggers a call to the system function with untrusted input from the request body for the SetNetworkTomographySettings API function, as demonstrated by shell metacharacters in the tomography_ping_number field.
CVE-2019-9116
Sublime Text 3, Sublimetext
Sublime_text_3
2021-07-21
N/A
7.8 HIGH
** DISPUTED ** DLL hijacking is possible in Sublime Text 3 version 3.1.1 build 3176 on 32-bit Windows platforms because a Trojan horse api-ms-win-core-fibers-l1-1-1.dll or api-ms-win-core-localization-l1-2-1.dll file may be loaded if a victim uses sublime_text.exe to open a .txt file within an attacker's %LOCALAPPDATA%Tempsublime_text folder. NOTE: the vendor's position is "This does not appear to be a bug with Sublime Text, but rather one with Windows that has been patched."
CVE-2019-9115
2021-07-21
N/A
9.8 CRITICAL
In irisnet-crypto before 1.1.7 for IRISnet, the util/utils.js file allows code execution because of unsafe eval usage.
CVE-2019-9114
2019-02-25
N/A
8.8 HIGH
Ming (aka libming) 0.4.8 has an out of bounds write vulnerability in the function strcpyext() in the decompile.c file in libutil.a.
CVE-2019-9113
2019-02-25
N/A
8.8 HIGH
Ming (aka libming) 0.4.8 has a NULL pointer dereference in the function getString() in the decompile.c file in libutil.a.
« Previous 1 … 5,119 5,120 5,121 5,122 5,123 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE