|
222541
|
5.5 |
MEDIUM
Local
|
intel
|
quartus_prime
|
Null pointer dereference in the FPGA kernel driver for Intel(R) Quartus(R) Prime Pro Edition before version 19.3 may allow an authenticated user to potentially enable denial of service via local acce…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-14604
|
2024-11-21 13:27 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222542
|
7.8 |
HIGH
Local
|
intel
|
quartus_prime
|
Improper permissions in the installer for the License Server software for Intel® Quartus® Prime Pro Edition before version 19.3 may allow an authenticated user to potentially enable escalation of pri…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-14603
|
2024-11-21 13:27 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222543
|
7.8 |
HIGH
Local
|
intel
|
control_center-i
|
Unquoted service path in Control Center-I version 2.1.0.0 and earlier may allow an authenticated user to potentially enable escalation of privilege via local access.
|
CWE-426
Untrusted Search Path
|
CVE-2019-14599
|
2024-11-21 13:27 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222544
|
5.4 |
MEDIUM
Network
|
redhat
|
3scale
|
A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to conduct cross site scripting attacks and gain acce…
|
-
|
CVE-2019-14849
|
2024-11-21 13:27 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222545
|
4.3 |
MEDIUM
Network
|
atlassian
|
crucible fisheye
|
The /json/profile/removeStarAjax.do resource in Atlassian Fisheye and Crucible before version 4.8.0 allows remote attackers to remove another user's favourite setting for a project via an improper au…
|
NVD-CWE-noinfo
|
CVE-2019-15009
|
2024-11-21 13:27 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222546
|
6.1 |
MEDIUM
Network
|
atlassian
|
crucible fisheye
|
The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulne…
|
CWE-79
Cross-site Scripting
|
CVE-2019-15008
|
2024-11-21 13:27 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222547
|
4.8 |
MEDIUM
Network
|
atlassian
|
crucible fisheye
|
The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the na…
|
CWE-79
Cross-site Scripting
|
CVE-2019-15007
|
2024-11-21 13:27 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222548
|
7.4 |
HIGH
Adjacent
|
freebsd linux openbsd apple
|
freebsd linux_kernel openbsd mac_os_x tvos iphone_os ipados macos
|
A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make pos…
|
-
|
CVE-2019-14899
|
2024-11-21 13:27 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222549
|
8.8 |
HIGH
Network
|
libssh canonical opensuse fedoraproject debian oracle
|
libssh ubuntu_linux leap fedora debian_linux mysql_workbench
|
A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided…
|
CWE-78
OS Command
|
CVE-2019-14889
|
2024-11-21 13:27 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222550
|
5.4 |
MEDIUM
Network
|
samba fedoraproject canonical debian opensuse
|
samba fedora ubuntu_linux debian_linux leap
|
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clie…
|
CWE-287
Improper Authentication
|
CVE-2019-14870
|
2024-11-21 13:27 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|