|
211531
|
6.1 |
MEDIUM
Network
|
audiocodes
|
mediant_500l-msbr_firmware mediant_500-mbsr_firmware mediant_m800b-msbr_firmware mediant_800c-msbr_firmware
|
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.253. A cross-site scripting (XSS) vulnerability in the sear…
|
CWE-79
Cross-site Scripting
|
CVE-2019-9230
|
2024-11-21 13:51 |
2019-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211532
|
5.3 |
MEDIUM
Network
|
mailvelope
|
mailvelope
|
Mailvelope prior to 3.3.0 does not require user interaction to import public keys shown on web page. This functionality can be tricked to either hide a key import from the user or obscure which key w…
|
CWE-320
Key Management Errors
|
CVE-2019-9150
|
2024-11-21 13:51 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211533
|
6.5 |
MEDIUM
Network
|
mailvelope
|
mailvelope
|
Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API. By modifying an URL parameter in Mailvelope, an attacker is able to sign (and encrypt) arbitrary m…
|
CWE-347 CWE-863
Improper Verification of Cryptographic Signature Incorrect Authorization
|
CVE-2019-9149
|
2024-11-21 13:51 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211534
|
4.3 |
MEDIUM
Network
|
mailvelope
|
mailvelope
|
Mailvelope prior to 3.3.0 accepts or operates with invalid PGP public keys: Mailvelope allows importing keys that contain users without a valid self-certification. Keys that are obviously invalid are…
|
CWE-295
Improper Certificate Validation
|
CVE-2019-9148
|
2024-11-21 13:51 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211535
|
4.3 |
MEDIUM
Network
|
mailvelope
|
mailvelope
|
Mailvelope prior to 3.1.0 is vulnerable to a clickjacking attack against the settings page. As the settings page is intended to be accessible from web applications, the browser's extension isolation …
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2019-9147
|
2024-11-21 13:51 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211536
|
9.8 |
CRITICAL
Network
|
jetbrains
|
intellij_idea
|
In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote attackers to execute code when the configuration is running, because a JMX server …
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2019-9186
|
2024-11-21 13:51 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211537
|
5.7 |
MEDIUM
Adjacent
|
gemalto
|
ezio_ds3_server
|
Gemalto DS3 Authentication Server 2.6.1-SP01 has Broken Access Control.
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2019-9158
|
2024-11-21 13:51 |
2019-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211538
|
5.7 |
MEDIUM
Adjacent
|
gemalto
|
ezio_ds3_server
|
Gemalto DS3 Authentication Server 2.6.1-SP01 allows Local File Disclosure.
|
CWE-22
Path Traversal
|
CVE-2019-9157
|
2024-11-21 13:51 |
2019-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211539
|
8.0 |
HIGH
Adjacent
|
gemalto
|
ezio_ds3_server
|
Gemalto DS3 Authentication Server 2.6.1-SP01 allows OS Command Injection.
|
CWE-78
OS Command
|
CVE-2019-9156
|
2024-11-21 13:51 |
2019-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211540
|
8.8 |
HIGH
Network
|
primasystems
|
flexair
|
Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when configuring the main central controller. These scripts can be immediately execu…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-9189
|
2024-11-21 13:51 |
2019-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|