|
222471
|
7.5 |
HIGH
Network
|
atlassian
|
jira_service_desk
|
The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before version 3.9.16, from version 3.10.0 before version 3.16.8, from version 4.0.0 before version…
|
CWE-22
Path Traversal
|
CVE-2019-14994
|
2024-11-21 13:27 |
2019-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222472
|
7.8 |
HIGH
Local
|
linux canonical debian fedoraproject opensuse netapp redhat huawei
|
linux_kernel ubuntu_linux debian_linux fedora leap aff_a700s_firmware h410c_firmware h610s_firmware h300s_firmware h500s_firmware h700s_firmware h300e_firmware h50…
|
A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migra…
|
-
|
CVE-2019-14835
|
2024-11-21 13:27 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222473
|
4.4 |
MEDIUM
Local
|
freeipa redhat
|
freeipa enterprise_linux
|
A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attacker could abuse this flaw if they obtain previously valid session cookies and ca…
|
CWE-613
Insufficient Session Expiration
|
CVE-2019-14826
|
2024-11-21 13:27 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222474
|
4.4 |
MEDIUM
Local
|
linux redhat canonical opensuse
|
linux_kernel enterprise_linux ubuntu_linux leap
|
In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via an interrupt. To exploit the venerability, a local user starts a trans…
|
CWE-662
Improper Synchronization
|
CVE-2019-15031
|
2024-11-21 13:27 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222475
|
4.4 |
MEDIUM
Local
|
linux redhat canonical opensuse
|
linux_kernel enterprise_linux ubuntu_linux leap
|
In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via a Facility Unavailable exception. To exploit the venerability, a local…
|
CWE-862
Missing Authorization
|
CVE-2019-15030
|
2024-11-21 13:27 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222476
|
5.3 |
MEDIUM
Network
|
easyappointments
|
easy\!appointments
|
Easy!Appointments 1.3.2 plugin for WordPress allows Sensitive Information Disclosure (Username and Password Hash).
|
NVD-CWE-noinfo
|
CVE-2019-14936
|
2024-11-21 13:27 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222477
|
6.5 |
MEDIUM
Network
|
atlassian
|
jira_server
|
The Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before version 8.4.0 allows remote attackers to bypass its protection via "cookie tossing" a CSRF cookie from a …
|
CWE-352
Origin Validation Error
|
CVE-2019-14998
|
2024-11-21 13:27 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222478
|
4.3 |
MEDIUM
Network
|
atlassian
|
jira_server
|
The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn details about other users, including their username, via an information expose through caching vulner…
|
NVD-CWE-Other
|
CVE-2019-14997
|
2024-11-21 13:27 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222479
|
6.1 |
MEDIUM
Network
|
atlassian
|
jira_server
|
The FilterPickerPopup.jspa resource in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scriptin…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14996
|
2024-11-21 13:27 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222480
|
5.3 |
MEDIUM
Network
|
atlassian
|
jira_server
|
The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an attachment with a specific name exists and if an issue key is valid via a missing p…
|
CWE-862
Missing Authorization
|
CVE-2019-14995
|
2024-11-21 13:27 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|