|
223281
|
6.5 |
MEDIUM
Network
|
serpico_project
|
serpico
|
An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. An admin can change their password without providing the current password, by using interfaces outside the…
|
CWE-287
Improper Authentication
|
CVE-2019-19857
|
2024-11-21 13:35 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223282
|
4.8 |
MEDIUM
Network
|
serpico_project
|
serpico
|
An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. The User Type on the admin/list_user page allows stored XSS via the type parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19856
|
2024-11-21 13:35 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223283
|
4.8 |
MEDIUM
Network
|
serpico_project
|
serpico
|
An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. admin/list_user allows stored XSS via the auth_type parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19855
|
2024-11-21 13:35 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223284
|
8.8 |
HIGH
Network
|
serpico_project
|
serpico
|
An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. It does not use CSRF Tokens to mitigate against CSRF; it uses the Origin header (which must match the requ…
|
CWE-352
Origin Validation Error
|
CVE-2019-19854
|
2024-11-21 13:35 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223285
|
8.8 |
HIGH
Network
|
proofpoint
|
enterprise_protection
|
A file-extension filtering vulnerability in Proofpoint Enterprise Protection (PPS / PoD), in the unpatched versions of PPS through 8.9.22 and 8.14.2 respectively, allows attackers to bypass protectio…
|
NVD-CWE-Other
|
CVE-2019-19680
|
2024-11-21 13:35 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223286
|
7.5 |
HIGH
Network
|
schedmd opensuse debian
|
slurm leap debian_linux
|
SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges.
|
CWE-269
Improper Privilege Management
|
CVE-2019-19728
|
2024-11-21 13:35 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223287
|
5.5 |
MEDIUM
Local
|
schedmd opensuse
|
slurm leap
|
SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 has weak slurmdbd.conf permissions.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-19727
|
2024-11-21 13:35 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223288
|
5.9 |
MEDIUM
Network
|
mitel
|
sip-dect_firmware
|
An encryption key vulnerability on Mitel SIP-DECT wireless devices 8.0 and 8.1 could allow an attacker to launch a man-in-the-middle attack. A successful exploit may allow the attacker to intercept s…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-19891
|
2024-11-21 13:35 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223289
|
5.5 |
MEDIUM
Local
|
gonitro
|
nitropdf
|
The JBIG2Globals library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x90ec NULL Pointer Dereference via crafted Unicode content.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-19819
|
2024-11-21 13:35 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223290
|
5.5 |
MEDIUM
Local
|
gonitro
|
nitro_free_pdf_reader
|
The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x2e8a Out-of-Bounds Read via crafted Unicode content.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-19817
|
2024-11-21 13:35 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|