|
222461
|
4.4 |
MEDIUM
Local
|
kaiostech
|
kaios
|
An issue was discovered in KaiOS 1.0, 2.5, and 2.5.1. The pre-installed Radio application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the R…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14759
|
2024-11-21 13:27 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222462
|
6.1 |
MEDIUM
Network
|
kaiostech
|
kaios
|
An issue was discovered in KaiOS 2.5 and 2.5.1. The pre-installed File Manager application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a file via email to the victim …
|
CWE-79
Cross-site Scripting
|
CVE-2019-14758
|
2024-11-21 13:27 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222463
|
6.1 |
MEDIUM
Network
|
kaiostech
|
kaios
|
An issue was discovered in KaiOS 2.5 and 2.5.1. The pre-installed Contacts application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a vCard file to the victim that wil…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14757
|
2024-11-21 13:27 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222464
|
6.1 |
MEDIUM
Network
|
kaiostech
|
kaios
|
An issue was discovered in KaiOS 1.0, 2.5, and 2.5.12.5. The pre-installed Email application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a specially crafted email to …
|
CWE-79
Cross-site Scripting
|
CVE-2019-14756
|
2024-11-21 13:27 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222465
|
7.3 |
HIGH
Local
|
redhat debian
|
ansible debian_linux
|
A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the 'ps' b…
|
-
|
CVE-2019-14904
|
2024-11-21 13:27 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222466
|
6.5 |
MEDIUM
Adjacent
|
intel
|
ax201_firmware ax200_firmware ac_9560_firmware ac_9462_firmware ac_9461_firmware ac_9260_firmware ac_8265_firmware ac_8260_firmware ac_3168_firmware ac_7265_firmware ac_…
|
Insufficient control flow management for some Intel(R) Wireless Bluetooth(R) products may allow an unprivileged user to potentially enable denial of service via adjacent access.
|
NVD-CWE-noinfo
|
CVE-2019-14620
|
2024-11-21 13:27 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222467
|
4.6 |
MEDIUM
Physics
|
intel
|
dsl3310_thunderbolt_firmware dsl3510_thunderbolt_firmware dsl4510_thunderbolt_firmware dsl4410_thunderbolt_firmware dsl5520_thunderbolt_2_firmware dsl5320_thunderbolt_2_firmware dsl…
|
Reliance on untrusted inputs in a security decision in some Intel(R) Thunderbolt(TM) controllers may allow unauthenticated user to potentially enable information disclosure via physical access.
|
NVD-CWE-noinfo
|
CVE-2019-14630
|
2024-11-21 13:27 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222468
|
6.5 |
MEDIUM
Network
|
hibernate redhat quarkus
|
hibernate_orm decision_manager openstack single_sign-on jboss_data_grid jboss_middleware_text-only_advisories jboss_enterprise_application_platform build_of_quarkus fuse qu…
|
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is us…
|
CWE-89
SQL Injection
|
CVE-2019-14900
|
2024-11-21 13:27 |
2020-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222469
|
7.2 |
HIGH
Network
|
redhat
|
cloudforms_management_engine
|
A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggered remote code execution through NFS schedule backup. An attacker logged into th…
|
-
|
CVE-2019-14894
|
2024-11-21 13:27 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222470
|
7.0 |
HIGH
Local
|
linux redhat
|
linux_kernel enterprise_mrg
|
The fix for CVE-2019-11599, affecting the Linux kernel before 5.0.10 was not complete. A local user could use this flaw to obtain sensitive information, cause a denial of service, or possibly have ot…
|
-
|
CVE-2019-14898
|
2024-11-21 13:27 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|