|
224381
|
5.3 |
MEDIUM
Network
|
eclipse
|
openj9
|
In Eclipse OpenJ9 prior to version 0.21 on Power platforms, calling the System.arraycopy method with a length longer than the length of the source or destination array can, in certain specially craft…
|
CWE-843
Type Confusion
|
CVE-2019-17639
|
2024-11-21 13:32 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224382
|
7.1 |
HIGH
Local
|
eclipse debian
|
web_tools_platform debian_linux
|
In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote serve…
|
CWE-611
XXE
|
CVE-2019-17637
|
2024-11-21 13:32 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224383
|
9.4 |
CRITICAL
Network
|
eclipse
|
jetty
|
In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce an HTTP 431 error. When this happens, the ByteBuffer conta…
|
CWE-672
Operation on a Resource after Expiration or Release
|
CVE-2019-17638
|
2024-11-21 13:32 |
2020-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224384
|
4.6 |
MEDIUM
Physics
|
biotronik
|
cardiomessenger_ii-s_gsm_firmware cardiomessenger_ii-s_t-line_firmware
|
BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverable format. An attacker with physical access to the CardioMessenger can use thes…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-18256
|
2024-11-21 13:32 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224385
|
4.6 |
MEDIUM
Physics
|
biotronik
|
cardiomessenger_ii-s_gsm_firmware cardiomessenger_ii-s_t-line_firmware
|
BIOTRONIK CardioMessenger II, The affected products do not encrypt sensitive information while at rest. An attacker with physical access to the CardioMessenger can disclose medical measurement data a…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2019-18254
|
2024-11-21 13:32 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224386
|
4.3 |
MEDIUM
Adjacent
|
biotronik
|
cardiomessenger_ii-s_gsm_firmware cardiomessenger_ii-s_t-line_firmware
|
BIOTRONIK CardioMessenger II, The affected products allow credential reuse for multiple authentication purposes. An attacker with adjacent access to the CardioMessenger can disclose its credentials u…
|
CWE-287
Improper Authentication
|
CVE-2019-18252
|
2024-11-21 13:32 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224387
|
4.3 |
MEDIUM
Adjacent
|
biotronik
|
cardiomessenger_ii-s_gsm_firmware cardiomessenger_ii-s_t-line_firmware
|
BIOTRONIK CardioMessenger II, The affected products transmit credentials in clear-text prior to switching to an encrypted communication channel. An attacker can disclose the product’s client credenti…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-18248
|
2024-11-21 13:32 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224388
|
4.3 |
MEDIUM
Adjacent
|
biotronik
|
cardiomessenger_ii-s_gsm_firmware cardiomessenger_ii-s_t-line_firmware
|
BIOTRONIK CardioMessenger II, The affected products do not properly enforce mutual authentication with the BIOTRONIK Remote Communication infrastructure.
|
CWE-287
Improper Authentication
|
CVE-2019-18246
|
2024-11-21 13:32 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224389
|
7.5 |
HIGH
Network
|
fortinet
|
fortios
|
A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6.2.2, 6.0.9 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an attacker to retrieve a …
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2019-17655
|
2024-11-21 13:32 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224390
|
7.8 |
HIGH
Local
|
asus
|
aura_sync
|
Ene.sys in Asus Aura Sync through 1.07.71 does not properly validate input to IOCTL 0x80102044, 0x80102050, and 0x80102054, which allows local users to cause a denial of service (system crash) or gai…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-17603
|
2024-11-21 13:32 |
2020-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|