|
222431
|
8.8 |
HIGH
Network
|
yeahlink
|
vp59_firmware t49g_firmware t58v_firmware
|
Yealink phones through 2019-08-04 have an issue with OpenVPN file upload. They execute tar as root to extract files, but do not validate the extraction directory. Creating a tar file with ../../../..…
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2019-14657
|
2024-11-21 13:27 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222432
|
8.8 |
HIGH
Network
|
yeahlink
|
vp59_firmware t49g_firmware t58v_firmware
|
Yealink phones through 2019-08-04 do not properly check user roles in POST requests. Consequently, the default User account (with a password of user) can make admin requests via HTTP.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-14656
|
2024-11-21 13:27 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222433
|
8.8 |
HIGH
Network
|
jetbrains
|
youtrack
|
JetBrains YouTrack versions before 2019.1 had a CSRF vulnerability on the settings page.
|
CWE-352
Origin Validation Error
|
CVE-2019-15040
|
2024-11-21 13:27 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222434
|
6.1 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
An issue was discovered in JetBrains TeamCity 2018.2.4. It had several XSS vulnerabilities on the settings pages. The issues were fixed in TeamCity 2019.1.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15037
|
2024-11-21 13:27 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222435
|
7.2 |
HIGH
Network
|
jetbrains
|
teamcity
|
An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could execute any command on the server machine. The issue was fixed in TeamCity 2018.2.5 and 2019.1.
|
CWE-78
OS Command
|
CVE-2019-15036
|
2024-11-21 13:27 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222436
|
5.9 |
MEDIUM
Network
|
jetbrains
|
toolbox
|
JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-14959
|
2024-11-21 13:27 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222437
|
7.5 |
HIGH
Network
|
jetbrains
|
pycharm
|
JetBrains PyCharm before 2019.2 was allocating a buffer of unknown size for one of the connection processes. In a very specific situation, it could lead to a remote invocation of an OOM error message…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-14958
|
2024-11-21 13:27 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222438
|
4.3 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
JetBrains YouTrack before 2019.2.53938 was using incorrect settings, allowing a user without necessary permissions to get other project names.
|
CWE-281
Improper Preservation of Permissions
|
CVE-2019-14956
|
2024-11-21 13:27 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222439
|
6.1 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality from an Untrusted Control Sphere.
|
CWE-601
Open Redirect
|
CVE-2019-15041
|
2024-11-21 13:27 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222440
|
4.9 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could get access to potentially confidential server-level data. The issue was fixed in TeamCity 2018.2.5 and 2…
|
NVD-CWE-noinfo
|
CVE-2019-15035
|
2024-11-21 13:27 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|