|
222831
|
6.1 |
MEDIUM
Network
|
cisco
|
managed_services_accelerator
|
A vulnerability in the web interface of Cisco Managed Services Accelerator (MSX) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due t…
|
CWE-20
Improper Input Validation
|
CVE-2019-15974
|
2024-11-21 13:29 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222832
|
6.1 |
MEDIUM
Network
|
cisco
|
web_security_appliance
|
A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a use…
|
CWE-79
Cross-site Scripting
|
CVE-2019-15969
|
2024-11-21 13:29 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222833
|
6.5 |
MEDIUM
Network
|
cisco
|
unified_communications_manager
|
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view sensitive information in the web-based management i…
|
NVD-CWE-noinfo
|
CVE-2019-15963
|
2024-11-21 13:29 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222834
|
6.6 |
MEDIUM
Physics
|
cisco
|
spa500_series_ip_phones_firmware
|
A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute arbitrary commands on the device. The vulnerability is due to the presence of de…
|
CWE-20
Improper Input Validation
|
CVE-2019-15959
|
2024-11-21 13:29 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222835
|
7.2 |
HIGH
Network
|
cisco
|
rv016_multi-wan_vpn_firmware rv042_dual_wan_vpn rv042g_dual_gigabit_wan_vpn_firmware rv082_dual_wan_vpn_router_firmware rv320_firmware rv325_firmware
|
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker with administrative privileges to inject arbitrar…
|
CWE-20
Improper Input Validation
|
CVE-2019-15957
|
2024-11-21 13:29 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222836
|
6.5 |
MEDIUM
Network
|
fortinet
|
fortiap-s fortiap-w2 fortiap-u
|
An improper input validation in FortiAP-S/W2 6.2.0 to 6.2.2, 6.0.5 and below, FortiAP-U 6.0.1 and below CLI admin console may allow unauthorized administrators to overwrite system files via specially…
|
CWE-20
Improper Input Validation
|
CVE-2019-15709
|
2024-11-21 13:29 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222837
|
9.8 |
CRITICAL
Network
|
freebsd
|
freebsd
|
In FreeBSD 12.1-STABLE before r356911, and 12.1-RELEASE before p5, insufficient checking in the cryptodev module allocated the size of a kernel buffer based on a user-supplied length allowing an unpr…
|
CWE-119 CWE-20
Incorrect Access of Indexable Resource ('Range Error') Improper Input Validation
|
CVE-2019-15880
|
2024-11-21 13:29 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222838
|
7.4 |
HIGH
Network
|
freebsd
|
freebsd
|
In FreeBSD 12.1-STABLE before r356908, 12.1-RELEASE before p5, 11.3-STABLE before r356908, and 11.3-RELEASE before p9, a race condition in the cryptodev module permitted a data structure in the kerne…
|
CWE-362 CWE-772
Race Condition Missing Release of Resource after Effective Lifetime
|
CVE-2019-15879
|
2024-11-21 13:29 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222839
|
7.8 |
HIGH
Local
|
freebsd
|
freebsd
|
In FreeBSD 12.1-STABLE before r352509, 11.3-STABLE before r352509, and 11.3-RELEASE before p9, an unprivileged local user can trigger a use-after-free situation due to improper checking in SCTP when …
|
CWE-416
Use After Free
|
CVE-2019-15878
|
2024-11-21 13:29 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222840
|
7.8 |
HIGH
Local
|
cisco
|
ios_xe
|
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due t…
|
CWE-20
Improper Input Validation
|
CVE-2019-16011
|
2024-11-21 13:29 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|