|
222931
|
7.8 |
HIGH
Local
|
intel
|
nuvoton_consumer_infrared
|
Improper permissions in the installer for the Nuvoton* CIR Driver versions 1.02.1002 and before may allow an authenticated user to potentially enable escalation of privilege via local access.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-14602
|
2024-11-21 13:27 |
2019-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222932
|
6.5 |
MEDIUM
Network
|
redhat
|
syndesis fuse
|
It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of protection to conduct phishing attacks and further acce…
|
NVD-CWE-Other
|
CVE-2019-14860
|
2024-11-21 13:27 |
2019-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222933
|
6.5 |
MEDIUM
Network
|
fedoraproject redhat debian
|
389_directory_server enterprise_linux debian_linux
|
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to vie…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-14824
|
2024-11-21 13:27 |
2019-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222934
|
4.3 |
MEDIUM
Network
|
atlassian
|
troubleshooting_and_support jira bitbucket confluence crowd fisheye crucible bamboo
|
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to…
|
CWE-862
Missing Authorization
|
CVE-2019-15005
|
2024-11-21 13:27 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222935
|
7.5 |
HIGH
Network
|
atlassian
|
jira_service_desk
|
The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from 3.10.0 before 3.16.10, from 4.0.0 before 4.2.6, from 4.3.0 before 4.3.5, from 4…
|
CWE-22
Path Traversal
|
CVE-2019-15004
|
2024-11-21 13:27 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222936
|
5.3 |
MEDIUM
Network
|
atlassian
|
jira_service_desk
|
The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from 3.10.0 before 3.16.10, from 4.0.0 before 4.2.6, from 4.3.0 before 4.3.5, from 4…
|
CWE-22
Path Traversal
|
CVE-2019-15003
|
2024-11-21 13:27 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222937
|
4.9 |
MEDIUM
Network
|
samba opensuse fedoraproject
|
samba leap fedora
|
A flaw was found in samba 4.0.0 before samba 4.9.15 and samba 4.10.x before 4.10.10. An attacker can crash AD DC LDAP server via dirsync resulting in denial of service. Privilege escalation is not po…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-14847
|
2024-11-21 13:27 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222938
|
5.4 |
MEDIUM
Network
|
samba opensuse fedoraproject
|
samba leap fedora
|
A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the way it handles a user password change or a new password for a samba user. The Sam…
|
CWE-521
Weak Password Requirements
|
CVE-2019-14833
|
2024-11-21 13:27 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222939
|
9.8 |
CRITICAL
Network
|
mitsubishielectric inea
|
smartrtu_firmware me-rtu_firmware
|
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote OS Command Injection vulnerability allows an atta…
|
CWE-78
OS Command
|
CVE-2019-14931
|
2024-11-21 13:27 |
2019-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222940
|
9.8 |
CRITICAL
Network
|
mitsubishielectric inea
|
smartrtu_firmware me-rtu_firmware
|
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Undocumented hard-coded user passwords for root, ineaadmin, mitsadmin, and …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-14930
|
2024-11-21 13:27 |
2019-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|