|
223681
|
8.8 |
HIGH
Network
|
artifex fedoraproject opensuse
|
ghostscript fedora leap
|
A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restricti…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-14869
|
2024-11-21 13:27 |
2019-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223682
|
10.0 |
CRITICAL
Network
|
sas
|
xml_mapper base_sas
|
SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Serve…
|
CWE-611
XXE
|
CVE-2019-14678
|
2024-11-21 13:27 |
2019-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223683
|
7.5 |
HIGH
Network
|
dpdk redhat fedoraproject
|
data_plane_development_kit enterprise_linux_fast_datapath openstack virtualization_eus fedora
|
A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user …
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-14818
|
2024-11-21 13:27 |
2019-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223684
|
7.8 |
HIGH
Local
|
intel
|
nuvoton_consumer_infrared
|
Improper permissions in the installer for the Nuvoton* CIR Driver versions 1.02.1002 and before may allow an authenticated user to potentially enable escalation of privilege via local access.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-14602
|
2024-11-21 13:27 |
2019-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223685
|
6.5 |
MEDIUM
Network
|
redhat
|
syndesis fuse
|
It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of protection to conduct phishing attacks and further acce…
|
NVD-CWE-Other
|
CVE-2019-14860
|
2024-11-21 13:27 |
2019-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223686
|
6.5 |
MEDIUM
Network
|
fedoraproject redhat debian
|
389_directory_server enterprise_linux debian_linux
|
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to vie…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-14824
|
2024-11-21 13:27 |
2019-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223687
|
4.3 |
MEDIUM
Network
|
atlassian
|
troubleshooting_and_support jira bitbucket confluence crowd fisheye crucible bamboo
|
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to…
|
CWE-862
Missing Authorization
|
CVE-2019-15005
|
2024-11-21 13:27 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223688
|
7.5 |
HIGH
Network
|
atlassian
|
jira_service_desk
|
The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from 3.10.0 before 3.16.10, from 4.0.0 before 4.2.6, from 4.3.0 before 4.3.5, from 4…
|
CWE-22
Path Traversal
|
CVE-2019-15004
|
2024-11-21 13:27 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223689
|
5.3 |
MEDIUM
Network
|
atlassian
|
jira_service_desk
|
The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from 3.10.0 before 3.16.10, from 4.0.0 before 4.2.6, from 4.3.0 before 4.3.5, from 4…
|
CWE-22
Path Traversal
|
CVE-2019-15003
|
2024-11-21 13:27 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223690
|
4.9 |
MEDIUM
Network
|
samba opensuse fedoraproject
|
samba leap fedora
|
A flaw was found in samba 4.0.0 before samba 4.9.15 and samba 4.10.x before 4.10.10. An attacker can crash AD DC LDAP server via dirsync resulting in denial of service. Privilege escalation is not po…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-14847
|
2024-11-21 13:27 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|