|
223231
|
9.8 |
CRITICAL
Network
|
onap
|
open_network_automation_platform
|
In ONAP OOM through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services witho…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-12127
|
2024-11-21 13:22 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223232
|
9.8 |
CRITICAL
Network
|
onap
|
open_network_automation_platform
|
In ONAP DCAE through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services with…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-12126
|
2024-11-21 13:22 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223233
|
9.8 |
CRITICAL
Network
|
onap
|
open_network_automation_platform
|
In ONAP Logging through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services w…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-12125
|
2024-11-21 13:22 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223234
|
6.1 |
MEDIUM
Network
|
apache
|
deltaspike
|
we got reports for 2 injection attacks against the DeltaSpike windowhandler.js. This is only active if a developer selected the ClientSideWindowStrategy which is not the default.
|
CWE-74
Injection
|
CVE-2019-12416
|
2024-11-21 13:22 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223235
|
9.8 |
CRITICAL
Network
|
onap
|
open_network_automation_platform
|
In ONAP CLI through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services witho…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-12130
|
2024-11-21 13:22 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223236
|
9.8 |
CRITICAL
Network
|
onap
|
open_network_automation_platform
|
In ONAP MSB through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services witho…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-12129
|
2024-11-21 13:22 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223237
|
9.8 |
CRITICAL
Network
|
onap
|
open_network_automation_platform
|
In ONAP SO through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services withou…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-12128
|
2024-11-21 13:22 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223238
|
6.1 |
MEDIUM
Network
|
readdle
|
spark
|
The Spark application through 2.0.2 for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12370
|
2024-11-21 13:22 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223239
|
6.1 |
MEDIUM
Network
|
typeapp
|
typeapp
|
The TypeApp application through 1.9.5.35 for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12369
|
2024-11-21 13:22 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223240
|
6.1 |
MEDIUM
Network
|
edison
|
edison_mail
|
The Edison Mail application through 1.7.1 for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12368
|
2024-11-21 13:22 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|