|
223751
|
5.4 |
MEDIUM
Network
|
redhat
|
3scale
|
A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to conduct cross site scripting attacks and gain acce…
|
-
|
CVE-2019-14849
|
2024-11-21 13:27 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223752
|
4.3 |
MEDIUM
Network
|
atlassian
|
crucible fisheye
|
The /json/profile/removeStarAjax.do resource in Atlassian Fisheye and Crucible before version 4.8.0 allows remote attackers to remove another user's favourite setting for a project via an improper au…
|
NVD-CWE-noinfo
|
CVE-2019-15009
|
2024-11-21 13:27 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223753
|
6.1 |
MEDIUM
Network
|
atlassian
|
crucible fisheye
|
The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulne…
|
CWE-79
Cross-site Scripting
|
CVE-2019-15008
|
2024-11-21 13:27 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223754
|
4.8 |
MEDIUM
Network
|
atlassian
|
crucible fisheye
|
The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the na…
|
CWE-79
Cross-site Scripting
|
CVE-2019-15007
|
2024-11-21 13:27 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223755
|
7.4 |
HIGH
Adjacent
|
freebsd linux openbsd apple
|
freebsd linux_kernel openbsd mac_os_x tvos iphone_os ipados macos
|
A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make pos…
|
-
|
CVE-2019-14899
|
2024-11-21 13:27 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223756
|
8.8 |
HIGH
Network
|
libssh canonical opensuse fedoraproject debian oracle
|
libssh ubuntu_linux leap fedora debian_linux mysql_workbench
|
A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided…
|
CWE-78
OS Command
|
CVE-2019-14889
|
2024-11-21 13:27 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223757
|
5.4 |
MEDIUM
Network
|
samba fedoraproject canonical debian opensuse
|
samba fedora ubuntu_linux debian_linux leap
|
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clie…
|
CWE-287
Improper Authentication
|
CVE-2019-14870
|
2024-11-21 13:27 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223758
|
5.3 |
MEDIUM
Network
|
samba fedoraproject canonical opensuse debian
|
samba fedora ubuntu_linux leap debian_linux
|
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS reco…
|
-
|
CVE-2019-14861
|
2024-11-21 13:27 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223759
|
9.8 |
CRITICAL
Network
|
redhat
|
keycloak
|
A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case user authentication…
|
CWE-295
Improper Certificate Validation
|
CVE-2019-14910
|
2024-11-21 13:27 |
2019-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223760
|
8.3 |
HIGH
Network
|
redhat
|
keycloak
|
A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted.
|
CWE-287
Improper Authentication
|
CVE-2019-14909
|
2024-11-21 13:27 |
2019-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|