|
223701
|
5.5 |
MEDIUM
Local
|
obdev
|
little_snitch
|
Little Snitch versions 4.4.0 fixes a vulnerability in a privileged helper tool. However, the operating system may have made a copy of the privileged helper which is not removed or updated immediately…
|
CWE-459
Incomplete Cleanup
|
CVE-2019-13014
|
2024-11-21 13:24 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223702
|
5.5 |
MEDIUM
Local
|
obdev
|
little_snitch
|
Little Snitch versions 4.3.0 to 4.3.2 have a local privilege escalation vulnerability in their privileged helper tool. The privileged helper tool implements an XPC interface which is available to any…
|
CWE-862
Missing Authorization
|
CVE-2019-13013
|
2024-11-21 13:24 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223703
|
8.8 |
HIGH
Network
|
search-guard
|
search_guard
|
Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an authenticated Kibana user could impersonate as kibanaserver user when providing wrong credentials when all …
|
NVD-CWE-noinfo
|
CVE-2019-13423
|
2024-11-21 13:24 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223704
|
6.1 |
MEDIUM
Network
|
search-guard
|
search_guard
|
Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an attacker can redirect the user to a potentially malicious site upon Kibana login.
|
CWE-601
Open Redirect
|
CVE-2019-13422
|
2024-11-21 13:24 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223705
|
4.9 |
MEDIUM
Network
|
search-guard
|
search_guard
|
Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database.
|
CWE-200
Information Exposure
|
CVE-2019-13421
|
2024-11-21 13:24 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223706
|
8.4 |
HIGH
Local
|
docker
|
docker
|
In Docker before 18.09.4, an attacker who is capable of supplying or manipulating the build path for the "docker build" command would be able to gain command execution. An issue exists in the way "do…
|
CWE-78
OS Command
|
CVE-2019-13139
|
2024-11-21 13:24 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223707
|
5.4 |
MEDIUM
Network
|
control-webpanel
|
webpanel
|
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, XSS in the domain parameter allows a low-privilege user to achieve root access via the email list page.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13476
|
2024-11-21 13:24 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223708
|
8.8 |
HIGH
Network
|
control-webpanel
|
webpanel
|
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, CSRF in the forgot password function allows an attacker to change the password for the root account.
|
CWE-352
Origin Validation Error
|
CVE-2019-13477
|
2024-11-21 13:24 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223709
|
6.5 |
MEDIUM
Network
|
otrs debian
|
otrs debian_linux
|
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, and Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. An attacker who is logged into OTRS as an agent …
|
NVD-CWE-noinfo
|
CVE-2019-13458
|
2024-11-21 13:24 |
2019-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223710
|
7.8 |
HIGH
Local
|
extenua
|
silvershield
|
extenua SilverSHielD 6.x fails to secure its ProgramData folder, leading to a Local Privilege Escalation to SYSTEM. The attacker must replace SilverShield.config.sqlite with a version containing an a…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-13069
|
2024-11-21 13:24 |
2019-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|