|
222981
|
7.5 |
HIGH
Network
|
jetbrains
|
teamcity
|
An issue was discovered in JetBrains TeamCity 2018.2.4. The TeamCity server was not using some security-related HTTP headers. The issue was fixed in TeamCity 2019.1.
|
NVD-CWE-noinfo
|
CVE-2019-15038
|
2024-11-21 13:27 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222982
|
7.8 |
HIGH
Local
|
jetbrains
|
rider
|
JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file.
|
CWE-426
Untrusted Search Path
|
CVE-2019-14960
|
2024-11-21 13:27 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222983
|
5.3 |
MEDIUM
Network
|
jetbrains
|
vim
|
The JetBrains Vim plugin before version 0.52 was storing individual project data in the global vim_settings.xml file. This xml file could be synchronized to a publicly accessible GitHub repository.
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2019-14957
|
2024-11-21 13:27 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222984
|
5.3 |
MEDIUM
Network
|
jetbrains
|
hub
|
In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no password expiration policy was implemented.
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2019-14955
|
2024-11-21 13:27 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222985
|
6.1 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox browser.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14953
|
2024-11-21 13:27 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222986
|
9.8 |
CRITICAL
Network
|
jetbrains
|
teamcity
|
An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in TeamCity 2019.1.
|
CWE-22
Path Traversal
|
CVE-2019-15039
|
2024-11-21 13:27 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222987
|
5.9 |
MEDIUM
Network
|
jetbrains
|
intellij_idea
|
JetBrains IntelliJ IDEA before 2019.2 was resolving the markdown plantuml artifact download link via a cleartext http connection.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-14954
|
2024-11-21 13:27 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222988
|
6.1 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
JetBrains YouTrack versions before 2019.1.52584 had a possible XSS in the issue titles.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14952
|
2024-11-21 13:27 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222989
|
6.1 |
MEDIUM
Network
|
salesagility
|
suitecrm
|
SuiteCRM 7.10.x and 7.11.x before 7.10.20 and 7.11.8 has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14752
|
2024-11-21 13:27 |
2019-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222990
|
7.5 |
HIGH
Network
|
mit fedoraproject
|
kerberos_5 fedora
|
A flaw was found in, Fedora versions of krb5 from 1.16.1 to, including 1.17.x, in the way a Kerberos client could crash the KDC by sending one of the RFC 4556 "enctypes". A remote unauthenticated use…
|
-
|
CVE-2019-14844
|
2024-11-21 13:27 |
2019-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|