|
223721
|
6.5 |
MEDIUM
Network
|
search-guard
|
search_guard
|
Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users can gain read access to data they are not authorized to see.
|
NVD-CWE-Other
|
CVE-2019-13415
|
2024-11-21 13:24 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223722
|
5.9 |
MEDIUM
Network
|
search-guard
|
search_guard
|
Search Guard versions before 21.0 had an timing side channel issue when using the internal user database.
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-13420
|
2024-11-21 13:24 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223723
|
7.5 |
HIGH
Network
|
search-guard
|
search_guard
|
Search Guard versions before 23.1 had an issue that for aggregations clear text values of anonymised fields were leaked.
|
CWE-200
Information Exposure
|
CVE-2019-13419
|
2024-11-21 13:24 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223724
|
7.5 |
HIGH
Network
|
search-guard
|
search_guard
|
Search Guard versions before 24.0 had an issue that values of string arrays in documents are not properly anonymized.
|
CWE-129
Improper Validation of Array Index
|
CVE-2019-13418
|
2024-11-21 13:24 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223725
|
5.3 |
MEDIUM
Network
|
search-guard
|
search_guard
|
Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activ…
|
CWE-200
Information Exposure
|
CVE-2019-13417
|
2024-11-21 13:24 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223726
|
9.1 |
CRITICAL
Network
|
lansweeper
|
lansweeper
|
Lansweeper before 7.1.117.4 allows unauthenticated SQL injection.
|
CWE-89
SQL Injection
|
CVE-2019-13462
|
2024-11-21 13:24 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223727
|
7.5 |
HIGH
Network
|
3cx
|
3cx
|
An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2. The Content.MainForm.wgx component is affected by XXE via a crafted XML document in POST dat…
|
CWE-611
XXE
|
CVE-2019-13176
|
2024-11-21 13:24 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223728
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-600m_firmware
|
An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-13101
|
2024-11-21 13:24 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223729
|
7.8 |
HIGH
Local
|
denx opensuse
|
u-boot leap
|
Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stack buffer overflow and likely code execution.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13106
|
2024-11-21 13:24 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223730
|
7.8 |
HIGH
Local
|
denx
|
u-boot
|
Das U-Boot versions 2019.07-rc1 through 2019.07-rc4 can double-free a cached block of data when listing files in a crafted ext4 filesystem.
|
CWE-415
Double Free
|
CVE-2019-13105
|
2024-11-21 13:24 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|