|
223571
|
9.8 |
CRITICAL
Network
|
squid-cache debian canonical
|
squid debian_linux ubuntu_linux
|
An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid by default comes with rules to block access to th…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-12524
|
2024-11-21 13:23 |
2020-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223572
|
4.5 |
MEDIUM
Local
|
squid-cache
|
squid
|
An issue was discovered in Squid through 4.7. When Squid is run as root, it spawns its child processes as a lesser user, by default the user nobody. This is done via the leave_suid call. leave_suid l…
|
CWE-269
Improper Privilege Management
|
CVE-2019-12522
|
2024-11-21 13:23 |
2020-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223573
|
5.9 |
MEDIUM
Network
|
squid-cache canonical debian opensuse
|
squid ubuntu_linux debian_linux leap
|
An issue was discovered in Squid through 4.7. When Squid is parsing ESI, it keeps the ESI elements in ESIContext. ESIContext contains a buffer for holding a stack of ESIElements. When a new ESIElemen…
|
CWE-787 CWE-193
Out-of-bounds Write Off-by-one Error
|
CVE-2019-12521
|
2024-11-21 13:23 |
2020-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223574
|
9.8 |
CRITICAL
Network
|
dlink
|
dap-1650_firmware
|
An issue was discovered on D-Link DAP-1650 devices before 1.04B02_J65H Hot Fix. Attackers can execute arbitrary commands.
|
CWE-78
OS Command
|
CVE-2019-12767
|
2024-11-21 13:23 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223575
|
6.5 |
MEDIUM
Network
|
graphicsmagick debian opensuse
|
graphicsmagick debian_linux leap backports_sle
|
In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG.
|
CWE-77
Command Injection
|
CVE-2019-12921
|
2024-11-21 13:23 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223576
|
8.8 |
HIGH
Network
|
solarwinds
|
serv-u_managed_file_transfer
|
SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 is vulnerable to Cross-Site Request Forgery in the file upload functionality via ?Command=Upload with the Dir and File …
|
CWE-352
Origin Validation Error
|
CVE-2019-12769
|
2024-11-21 13:23 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223577
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. Unauthorized users were able to read pipeline information of the last merge request. It has Incorrect Access C…
|
NVD-CWE-noinfo
|
CVE-2019-13002
|
2024-11-21 13:23 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223578
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition 11.9 and later through 12.0.2. GitLab Snippets were vulnerable to an authorization issue that allowed unauthorized users to add comm…
|
CWE-863
Incorrect Authorization
|
CVE-2019-13001
|
2024-11-21 13:23 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223579
|
4.8 |
MEDIUM
Network
|
solarwinds
|
netpath orion_platform network_performance_monitor
|
SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) allows Stored HTML Injection by administrators via the Web Console Settings screen.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12863
|
2024-11-21 13:23 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223580
|
9.1 |
CRITICAL
Network
|
netgear
|
nighthawk_x10-r9000_firmware
|
In NETGEAR Nighthawk X10-R900 prior to 1.0.4.26, an attacker may bypass all authentication checks on the device's "NETGEAR Genie" SOAP API ("/soap/server_sa") by supplying a malicious X-Forwarded-For…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-12510
|
2024-11-21 13:23 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|