CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
In heap of spaces.h, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure when processing a proxy auto config file with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9 Android ID: A-117555811
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it only affected a development version. Notes: none.
service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via shell metacharacters in the kuid parameter.
usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.
An issue was discovered in EFS Easy Chat Server 3.1. There is a buffer overflow via a long body2.ghp message parameter.
Dir-825/ac_g1_firmware, Dir-825/ac_g1, Dsl-2875al_firmware, Dsl-2875al, Dsl-2877al_firmware, Dsl-2877al, Dap-1360_revision_f_firmware, Dap-1360_revision_f, Dsl-2680_firmware, Dsl-2680
2020-03-06
N/A
7.8 HIGH
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Upgrade Firmware functionality in the Web interface, using shell metacharacters in the admin.cgi?action=upgrade firmwareRestore or firmwareServerip parameter.
Dir-825/ac_g1_firmware, Dir-825/ac_g1, Dsl-2875al_firmware, Dsl-2875al, Dsl-2877al_firmware, Dsl-2877al, Dap-1360_revision_f_firmware, Dap-1360_revision_f, Dsl-2680_firmware, Dsl-2680
2020-03-06
N/A
7.8 HIGH
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter.
In tearDownClientInterface of WificondControl.java, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0 Android-8.1 Android-9 Android ID: A-121327323
Dir-825/ac_g1_firmware, Dir-825/ac_g1, Dsl-2875al_firmware, Dsl-2875al, Dsl-2877al_firmware, Dsl-2877al, Dap-1360_revision_f_firmware, Dap-1360_revision_f, Dsl-2680_firmware, Dsl-2680
2020-03-28
N/A
7.8 HIGH
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_restore configRestore or configServerip parameter.
cPanel before 82.0.18 allows WebDAV authentication bypass because the connection-sharing logic is incorrect (SEC-534).
