|
222831
|
9.8 |
CRITICAL
Network
|
adremsoft
|
netcrunch
|
AdRem NetCrunch 10.6.0.4587 has a hardcoded SSL private key vulnerability in the NetCrunch web client. The same hardcoded SSL private key is used across different customers' installations when no oth…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-14482
|
2024-11-21 13:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222832
|
9.8 |
CRITICAL
Network
|
adremsoft
|
netcrunch
|
AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or escalation of privileges.
|
CWE-200 CWE-338 CWE-311 CWE-522 CWE-732
Information Exposure Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) Missing Encryption of Sensitive Data Insufficiently Protected Credentials Incorrect Permission Assignment for Critical Resource
|
CVE-2019-14480
|
2024-11-21 13:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222833
|
5.5 |
MEDIUM
Local
|
adremsoft
|
netcrunch
|
AdRem NetCrunch 10.6.0.4587 has Improper Credential Storage since the internal user database is readable by low-privileged users and passwords in the database are weakly encoded or encrypted.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-14477
|
2024-11-21 13:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222834
|
6.5 |
MEDIUM
Adjacent
|
tianocore debian
|
edk2 debian_linux
|
Logic issue EDK II may allow an unauthenticated user to potentially enable denial of service via adjacent access.
|
NVD-CWE-noinfo
|
CVE-2019-14587
|
2024-11-21 13:26 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222835
|
8.0 |
HIGH
Adjacent
|
tianocore debian
|
edk2 debian_linux
|
Use after free vulnerability in EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via adjacent access.
|
CWE-416
Use After Free
|
CVE-2019-14586
|
2024-11-21 13:26 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222836
|
7.8 |
HIGH
Local
|
tianocore debian
|
edk2 debian_linux
|
Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.
|
NVD-CWE-noinfo
|
CVE-2019-14575
|
2024-11-21 13:26 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222837
|
7.8 |
HIGH
Local
|
tianocore debian
|
edk2 debian_linux
|
Integer truncation in EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.
|
CWE-787 CWE-681
Out-of-bounds Write Incorrect Conversion between Numeric Types
|
CVE-2019-14563
|
2024-11-21 13:26 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222838
|
5.5 |
MEDIUM
Local
|
tianocore debian
|
edk2 debian_linux
|
Integer overflow in DxeImageVerificationHandler() EDK II may allow an authenticated user to potentially enable denial of service via local access.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-14562
|
2024-11-21 13:26 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222839
|
7.5 |
HIGH
Network
|
tianocore
|
edk2
|
Uncontrolled resource consumption in EDK II may allow an unauthenticated user to potentially enable denial of service via network access.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-14559
|
2024-11-21 13:26 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222840
|
4.9 |
MEDIUM
Network
|
tianocore
|
edk2
|
Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network access.
|
CWE-287
Improper Authentication
|
CVE-2019-14553
|
2024-11-21 13:26 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|