|
222641
|
7.8 |
HIGH
Local
|
tianocore
|
edk2
|
Null pointer dereference in Tianocore EDK2 may allow an authenticated user to potentially enable escalation of privilege via local access.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-14584
|
2024-11-21 13:26 |
2021-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222642
|
5.4 |
MEDIUM
Network
|
adremsoft
|
netcrunch
|
AdRem NetCrunch 10.6.0.4587 has a Cross-Site Request Forgery (CSRF) vulnerability in the NetCrunch web client. Successful exploitation requires a logged-in user to open a malicious page and leads to …
|
CWE-352
Origin Validation Error
|
CVE-2019-14481
|
2024-11-21 13:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222643
|
8.8 |
HIGH
Network
|
adremsoft
|
netcrunch
|
AdRem NetCrunch 10.6.0.4587 allows Remote Code Execution. In the NetCrunch web client, a read-only administrator can execute arbitrary code on the server running the NetCrunch server software.
|
CWE-78
OS Command
|
CVE-2019-14479
|
2024-11-21 13:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222644
|
5.4 |
MEDIUM
Network
|
adremsoft
|
netcrunch
|
AdRem NetCrunch 10.6.0.4587 has a stored Cross-Site Scripting (XSS) vulnerability in the NetCrunch web client. The user's input data is not properly encoded when being echoed back to the user. This d…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14478
|
2024-11-21 13:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222645
|
6.5 |
MEDIUM
Network
|
adremsoft
|
netcrunch
|
AdRem NetCrunch 10.6.0.4587 has a Server-Side Request Forgery (SSRF) vulnerability in the NetCrunch server. Every user can trick the server into performing SMB requests to other systems.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-14476
|
2024-11-21 13:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222646
|
8.8 |
HIGH
Network
|
adremsoft
|
netcrunch
|
AdRem NetCrunch 10.6.0.4587 allows Credentials Disclosure. Every user can read the BSD, Linux, MacOS and Solaris private keys, private keys' passwords, and root passwords stored in the credential man…
|
NVD-CWE-noinfo
|
CVE-2019-14483
|
2024-11-21 13:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222647
|
9.8 |
CRITICAL
Network
|
adremsoft
|
netcrunch
|
AdRem NetCrunch 10.6.0.4587 has a hardcoded SSL private key vulnerability in the NetCrunch web client. The same hardcoded SSL private key is used across different customers' installations when no oth…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-14482
|
2024-11-21 13:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222648
|
9.8 |
CRITICAL
Network
|
adremsoft
|
netcrunch
|
AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or escalation of privileges.
|
CWE-200 CWE-338 CWE-311 CWE-522 CWE-732
Information Exposure Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) Missing Encryption of Sensitive Data Insufficiently Protected Credentials Incorrect Permission Assignment for Critical Resource
|
CVE-2019-14480
|
2024-11-21 13:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222649
|
5.5 |
MEDIUM
Local
|
adremsoft
|
netcrunch
|
AdRem NetCrunch 10.6.0.4587 has Improper Credential Storage since the internal user database is readable by low-privileged users and passwords in the database are weakly encoded or encrypted.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-14477
|
2024-11-21 13:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222650
|
6.5 |
MEDIUM
Adjacent
|
tianocore debian
|
edk2 debian_linux
|
Logic issue EDK II may allow an unauthenticated user to potentially enable denial of service via adjacent access.
|
NVD-CWE-noinfo
|
CVE-2019-14587
|
2024-11-21 13:26 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|