|
223341
|
7.5 |
HIGH
Network
|
search-guard
|
search_guard
|
Search Guard versions before 23.1 had an issue that for aggregations clear text values of anonymised fields were leaked.
|
CWE-200
Information Exposure
|
CVE-2019-13419
|
2024-11-21 13:24 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223342
|
7.5 |
HIGH
Network
|
search-guard
|
search_guard
|
Search Guard versions before 24.0 had an issue that values of string arrays in documents are not properly anonymized.
|
CWE-129
Improper Validation of Array Index
|
CVE-2019-13418
|
2024-11-21 13:24 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223343
|
5.3 |
MEDIUM
Network
|
search-guard
|
search_guard
|
Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activ…
|
CWE-200
Information Exposure
|
CVE-2019-13417
|
2024-11-21 13:24 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223344
|
9.1 |
CRITICAL
Network
|
lansweeper
|
lansweeper
|
Lansweeper before 7.1.117.4 allows unauthenticated SQL injection.
|
CWE-89
SQL Injection
|
CVE-2019-13462
|
2024-11-21 13:24 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223345
|
7.5 |
HIGH
Network
|
3cx
|
3cx
|
An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2. The Content.MainForm.wgx component is affected by XXE via a crafted XML document in POST dat…
|
CWE-611
XXE
|
CVE-2019-13176
|
2024-11-21 13:24 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223346
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-600m_firmware
|
An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-13101
|
2024-11-21 13:24 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223347
|
7.8 |
HIGH
Local
|
denx opensuse
|
u-boot leap
|
Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stack buffer overflow and likely code execution.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13106
|
2024-11-21 13:24 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223348
|
7.8 |
HIGH
Local
|
denx
|
u-boot
|
Das U-Boot versions 2019.07-rc1 through 2019.07-rc4 can double-free a cached block of data when listing files in a crafted ext4 filesystem.
|
CWE-415
Double Free
|
CVE-2019-13105
|
2024-11-21 13:24 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223349
|
7.8 |
HIGH
Local
|
denx opensuse
|
u-boot leap
|
In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite a very large amount of data (including the whole stack) while reading a crafted ext4 filesystem.
|
CWE-787 CWE-191
Out-of-bounds Write Integer Underflow (Wrap or Wraparound)
|
CVE-2019-13104
|
2024-11-21 13:24 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223350
|
9.8 |
CRITICAL
Network
|
shenzhen_dragon_brothers
|
fb50_firmware
|
An HTTP parameter pollution issue was discovered on Shenzhen Dragon Brothers Fingerprint Bluetooth Round Padlock FB50 2.3. With the user ID, user name, and the lock's MAC address, anyone can unbind t…
|
CWE-20
Improper Input Validation
|
CVE-2019-13143
|
2024-11-21 13:24 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|