|
222621
|
7.5 |
HIGH
Network
|
jetbrains
|
pycharm
|
JetBrains PyCharm before 2019.2 was allocating a buffer of unknown size for one of the connection processes. In a very specific situation, it could lead to a remote invocation of an OOM error message…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-14958
|
2024-11-21 13:27 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222622
|
4.3 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
JetBrains YouTrack before 2019.2.53938 was using incorrect settings, allowing a user without necessary permissions to get other project names.
|
CWE-281
Improper Preservation of Permissions
|
CVE-2019-14956
|
2024-11-21 13:27 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222623
|
6.1 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality from an Untrusted Control Sphere.
|
CWE-601
Open Redirect
|
CVE-2019-15041
|
2024-11-21 13:27 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222624
|
4.9 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could get access to potentially confidential server-level data. The issue was fixed in TeamCity 2018.2.5 and 2…
|
NVD-CWE-noinfo
|
CVE-2019-15035
|
2024-11-21 13:27 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222625
|
7.5 |
HIGH
Network
|
jetbrains
|
teamcity
|
An issue was discovered in JetBrains TeamCity 2018.2.4. It had no SSL certificate validation for some external https connections. This was fixed in TeamCity 2019.1.
|
CWE-295
Improper Certificate Validation
|
CVE-2019-15042
|
2024-11-21 13:27 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222626
|
6.1 |
MEDIUM
Network
|
jetbrains
|
upsource
|
JetBrains Upsource before 2019.1.1412 was not properly escaping HTML tags in a code block comments, leading to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14961
|
2024-11-21 13:27 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222627
|
7.5 |
HIGH
Network
|
jetbrains
|
teamcity
|
An issue was discovered in JetBrains TeamCity 2018.2.4. The TeamCity server was not using some security-related HTTP headers. The issue was fixed in TeamCity 2019.1.
|
NVD-CWE-noinfo
|
CVE-2019-15038
|
2024-11-21 13:27 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222628
|
7.8 |
HIGH
Local
|
jetbrains
|
rider
|
JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file.
|
CWE-426
Untrusted Search Path
|
CVE-2019-14960
|
2024-11-21 13:27 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222629
|
5.3 |
MEDIUM
Network
|
jetbrains
|
vim
|
The JetBrains Vim plugin before version 0.52 was storing individual project data in the global vim_settings.xml file. This xml file could be synchronized to a publicly accessible GitHub repository.
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2019-14957
|
2024-11-21 13:27 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222630
|
5.3 |
MEDIUM
Network
|
jetbrains
|
hub
|
In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no password expiration policy was implemented.
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2019-14955
|
2024-11-21 13:27 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|