|
222601
|
8.8 |
HIGH
Network
|
siemens
|
sppa-t3000_application_server
|
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with valid authentication at the RMI interface could be able to gain remote co…
|
CWE-787 CWE-434
Out-of-bounds Write Unrestricted Upload of File with Dangerous Type
|
CVE-2019-18288
|
2024-11-21 13:32 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222602
|
5.3 |
MEDIUM
Network
|
siemens
|
sppa-t3000_application_server
|
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The Application Server exposes directory listings and files containing sensitive informati…
|
CWE-200
Information Exposure
|
CVE-2019-18287
|
2024-11-21 13:32 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222603
|
5.3 |
MEDIUM
Network
|
siemens
|
sppa-t3000_application_server
|
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The Application Server exposes directory listings and files containing sensitive informati…
|
CWE-200
Information Exposure
|
CVE-2019-18286
|
2024-11-21 13:32 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222604
|
5.9 |
MEDIUM
Network
|
siemens
|
sppa-t3000_application_server
|
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The RMI communication between the client and the Application Server is unencrypted. An att…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-18285
|
2024-11-21 13:32 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222605
|
9.8 |
CRITICAL
Network
|
siemens
|
sppa-t3000_application_server
|
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without authentication on the Application Server. An attacke…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-18284
|
2024-11-21 13:32 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222606
|
9.8 |
CRITICAL
Network
|
siemens
|
sppa-t3000_application_server
|
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without authentication on the Application Server. An attacke…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-18283
|
2024-11-21 13:32 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222607
|
7.8 |
HIGH
Local
|
reliablecontrols
|
rc-licensemanager
|
Reliable Controls LicenseManager versions 3.4 and prior may allow an authenticated user to insert malicious code into the system root path, which may allow execution of code with elevated privileges …
|
CWE-428
Unquoted Search Path or Element
|
CVE-2019-18245
|
2024-11-21 13:32 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222608
|
7.8 |
HIGH
Local
|
gemalto
|
sentinel_ldk_license_manager
|
SafeNet Sentinel LDK License Manager, all versions prior to 7.101(only Microsoft Windows versions are affected) is vulnerable when configured as a service. This vulnerability may allow an attacker wi…
|
CWE-59
Link Following
|
CVE-2019-18232
|
2024-11-21 13:32 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222609
|
9.8 |
CRITICAL
Network
|
yachtcontrol
|
yachtcontrol
|
Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user via the "/pages/systemcall.php?command={COMMAND}" page and parameter, where {COMM…
|
CWE-78
OS Command
|
CVE-2019-17270
|
2024-11-21 13:32 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222610
|
9.8 |
CRITICAL
Network
|
trendmicro
|
antivirus\+_security_2020 internet_security_2020 maximum_security_2020 premium_security_2020
|
Trend Micro Security (Consumer) 2020 (v16.x) is affected by a vulnerability in where null pointer dereference errors result in the crash of application, which could potentially lead to possible unsig…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-18190
|
2024-11-21 13:32 |
2019-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|