CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a stack-based buffer overflow in the function SVGStartElement of coders/svg.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a quoted font family value.
In Materialize through 1.0.0, XSS is possible via the Toast feature.
In Materialize through 1.0.0, XSS is possible via the Autocomplete feature.
In Materialize through 1.0.0, XSS is possible via the Tooltip feature.
Rlc-410w_firmware, Rlc-410w, C1_pro_firmware, C1_pro, C2_pro_firmware, C2_pro, Rlc-422w_firmware, Rlc-422w, Rlc-511w_firmware, Rlc-511w
2019-04-09
N/A
7.2 HIGH
On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated by shell metacharacters in the addr1 field.
An issue was discovered in GitLab Enterprise Edition before 11.7.11, 11.8.x before 11.8.7, and 11.9.x before 11.9.7. It allows Information Disclosure.
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1094, CVE-2019-1095, CVE-2019-1098, CVE-2019-1099, CVE-2019-1101, CVE-2019-1116.
Dir-816_firmware, Dir-816, Dsl-2750u_firmware, Dsl-2750u, Dir-806_firmware, Dir-806, Dcs-930l_firmware, Dcs-930l, Dcs-931l_firmware, Dcs-931l
2020-08-24
N/A
8.8 HIGH
The D-Link DCS series of Wi-Fi cameras contains a stack-based buffer overflow in alphapd, the camera's web server. The overflow allows a remotely authenticated attacker to execute arbitrary code by providing a long string in the WEPEncryption parameter when requesting wireless.htm. Vulnerable devices include DCS-5009L (1.08.11 and below), DCS-5010L (1.14.09 and below), DCS-5020L (1.15.12 and below), DCS-5025L (1.03.07 and below), DCS-5030L (1.04.10 and below), DCS-930L (2.16.01 and below), DCS-931L (1.14.11 and below), DCS-932L (2.17.01 and below), DCS-933L (1.14.11 and below), and DCS-934L (1.05.04 and below).
Ilc_151_eth_firmware, Ilc_151_eth, Axc_f_2152_firmware, Axc_f_2152, Axc_f_2152_starterkit_firmware, Axc_f_2152_starterkit, Fl_nat_2208_firmware, Fl_nat_2208, Fl_nat_2304-2gc-2sfp_firmware, Fl_nat_2304-2gc-2sfp
2019-06-20
N/A
6.8 MEDIUM
An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices. Unlimited physical access to the PLC may lead to a manipulation of SD cards data. SD card manipulation may lead to an authentication bypass opportunity.
Ilc_151_eth_firmware, Ilc_151_eth, Axc_f_2152_firmware, Axc_f_2152, Axc_f_2152_starterkit_firmware, Axc_f_2152_starterkit, Fl_nat_2208_firmware, Fl_nat_2208, Fl_nat_2304-2gc-2sfp_firmware, Fl_nat_2304-2gc-2sfp
2020-08-24
N/A
5.9 MEDIUM
An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices. Protocol Fuzzing on PC WORX Engineer by a man in the middle attacker stops the PLC service. The device must be rebooted, or the PLC service must be restarted manually via a Linux shell.
