• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-18831
Barco, Clickshare Cse-800, Clickshare Cse-800 Firmware
Clickshare_button_r9861500d01_firmware, Clickshare_button_r9861500d01, Clickshare_cs-100_huddle_firmware, Clickshare_cs-100_huddle, Clickshare_cse-200_firmware, Clickshare_cse-200, Clickshare_cs-100_firmware, Clickshare_cs-100, Clickshare_cse-800_firmware, Clickshare_cse-800
2020-08-24
N/A
5.3 MEDIUM
Barco ClickShare Button R9861500D01 devices before 1.9.0 allow Information Exposure. The encrypted ClickShare Button firmware contains the private key of a test device-certificate.
CVE-2019-18830
Barco, Clickshare Cse-800, Clickshare Cse-800 Firmware
Clickshare_button_r9861500d01_firmware, Clickshare_button_r9861500d01, Clickshare_cs-100_huddle_firmware, Clickshare_cs-100_huddle, Clickshare_cse-200_firmware, Clickshare_cse-200, Clickshare_cs-100_firmware, Clickshare_cs-100, Clickshare_cse-800_firmware, Clickshare_cse-800
2019-12-23
N/A
9.8 CRITICAL
Barco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection. The embedded 'dongle_bridge' program used to expose the functionalities of the ClickShare Button to a USB host, is vulnerable to OS command injection vulnerabilities. These vulnerabilities could lead to code execution on the ClickShare Button with the privileges of the user 'nobody'.
CVE-2019-1883
Cisco, Encs 5400
Sd-wan_firmware, Vedge-100, Vedge-1000, Vedge-100b, Vedge-2000, Vedge-5000, Vedge_100m, Vedge_100wm, Hyperflex_hx220c_m5_firmware, Hyperflex_hx220c_m5
2019-10-09
N/A
7.8 HIGH
A vulnerability in the command-line interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker with read-only credentials to inject arbitrary commands that could allow them to obtain root privileges. The vulnerability is due to insufficient validation of user-supplied input on the command-line interface. An attacker could exploit this vulnerability by authenticating with read-only privileges via the CLI of an affected device and submitting crafted input to the affected commands. A successful exploit could allow an attacker to execute arbitrary commands on the device with root privileges.
CVE-2019-18829
Barco, Clickshare Button R9861500d01, Clickshare Button R9861500d01 Firmware
Clickshare_button_r9861500d01_firmware, Clickshare_button_r9861500d01, Clickshare_cs-100_huddle_firmware, Clickshare_cs-100_huddle, Clickshare_cse-200_firmware, Clickshare_cse-200, Clickshare_cs-100_firmware, Clickshare_cs-100, Clickshare_cse-800_firmware, Clickshare_cse-800
2021-07-21
N/A
7.8 HIGH
Barco ClickShare Button R9861500D01 devices before 1.10.0.13 have Missing Support for Integrity Check. The Barco signed 'Clickshare_For_Windows.exe' binary on the ClickShare Button (R9861500D01) loads a number of DLL files dynamically without verifying their integrity.
CVE-2019-18828
Barco, Clickshare Cse-800, Clickshare Cse-800 Firmware
Clickshare_button_r9861500d01_firmware, Clickshare_button_r9861500d01, Clickshare_cs-100_huddle_firmware, Clickshare_cs-100_huddle, Clickshare_cse-200_firmware, Clickshare_cse-200, Clickshare_cs-100_firmware, Clickshare_cs-100, Clickshare_cse-800_firmware, Clickshare_cse-800
2020-08-24
N/A
6.8 MEDIUM
Barco ClickShare Button R9861500D01 devices before 1.9.0 have Insufficiently Protected Credentials. The root account (present for access via debug interfaces, which are by default not enabled on production devices) of the embedded Linux on the ClickShare Button is using a weak password.
CVE-2019-18827
Barco, Clickshare Cse-800, Clickshare Cse-800 Firmware
Clickshare_button_r9861500d01_firmware, Clickshare_button_r9861500d01, Clickshare_cs-100_huddle_firmware, Clickshare_cs-100_huddle, Clickshare_cse-200_firmware, Clickshare_cse-200, Clickshare_cs-100_firmware, Clickshare_cs-100, Clickshare_cse-800_firmware, Clickshare_cse-800
2021-07-21
N/A
5.9 MEDIUM
On Barco ClickShare Button R9861500D01 devices (before firmware version 1.9.0) JTAG access is disabled after ROM code execution. This means that JTAG access is possible when the system is running code from ROM before handing control over to embedded firmware.
CVE-2019-18826
Barco, Clickshare Cse-800, Clickshare Cse-800 Firmware
Clickshare_button_r9861500d01_firmware, Clickshare_button_r9861500d01, Clickshare_cs-100_huddle_firmware, Clickshare_cs-100_huddle, Clickshare_cse-200_firmware, Clickshare_cse-200, Clickshare_cs-100_firmware, Clickshare_cs-100, Clickshare_cse-800_firmware, Clickshare_cse-800
2019-12-27
N/A
9.8 CRITICAL
Barco ClickShare Button R9861500D01 devices before 1.9.0 have Improper Following of a Certificate's Chain of Trust. The embedded 'dongle_bridge' program used to expose the functionalities of the ClickShare Button to a USB host, does not properly validate the whole certificate chain.
CVE-2019-18825
Barco, Clickshare Cse-200, Clickshare Cse-200 Firmware
Clickshare_button_r9861500d01_firmware, Clickshare_button_r9861500d01, Clickshare_cs-100_huddle_firmware, Clickshare_cs-100_huddle, Clickshare_cse-200_firmware, Clickshare_cse-200, Clickshare_cs-100_firmware, Clickshare_cs-100, Clickshare_cse-800_firmware, Clickshare_cse-800
2019-12-26
N/A
7.5 HIGH
Barco ClickShare Huddle CS-100 devices before 1.9.0 and CSE-200 devices before 1.9.0 have incorrect Credentials Management. The ClickShare Base Unit implements encryption at rest using encryption keys which are shared across all ClickShare Base Units of models CS-100 & CSE-200.
CVE-2019-18824
Barco, Clickshare Button R9861500d01, Clickshare Button R9861500d01 Firmware
Clickshare_button_r9861500d01_firmware, Clickshare_button_r9861500d01, Clickshare_cs-100_huddle_firmware, Clickshare_cs-100_huddle, Clickshare_cse-200_firmware, Clickshare_cse-200, Clickshare_cs-100_firmware, Clickshare_cs-100, Clickshare_cse-800_firmware, Clickshare_cse-800
2021-07-21
N/A
6.6 MEDIUM
Barco ClickShare Button R9861500D01 devices before 1.10.0.13 have Missing Support for Integrity Check. The ClickShare Button does not verify the integrity of the mutable content on the UBIFS partition before being used.
CVE-2019-18823
2022-10-06
N/A
9.8 CRITICAL
HTCondor up to and including stable series 8.8.6 and development series 8.9.4 has Incorrect Access Control. It is possible to use a different authentication method to submit a job than the administrator has specified. If the administrator has configured the READ or WRITE methods to include CLAIMTOBE, then it is possible to impersonate another user to the condor_schedd. (For example to submit or remove jobs)
« Previous 1 … 5,849 5,850 5,851 5,852 5,853 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE