|
211571
|
3.7 |
LOW
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 1 of 5).
|
CWE-862
Missing Authorization
|
CVE-2019-9171
|
2024-11-21 13:51 |
2019-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211572
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-9170
|
2024-11-21 13:51 |
2019-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211573
|
8.1 |
HIGH
Network
|
w1.fi fedoraproject opensuse debian synology freebsd
|
hostapd wpa_supplicant fedora leap backports_sle debian_linux router_manager radius_server freebsd
|
The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-p…
|
CWE-287
Improper Authentication
|
CVE-2019-9499
|
2024-11-21 13:51 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211574
|
8.1 |
HIGH
Network
|
w1.fi fedoraproject opensuse debian synology freebsd
|
hostapd wpa_supplicant fedora leap backports_sle debian_linux router_manager radius_server freebsd
|
The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Co…
|
CWE-287
Improper Authentication
|
CVE-2019-9498
|
2024-11-21 13:51 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211575
|
8.1 |
HIGH
Network
|
w1.fi fedoraproject
|
hostapd wpa_supplicant fedora
|
The implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer do not validate the scalar and element values in EAP-pwd-Commit. This vulnerability may allow an attacker to complete …
|
CWE-287
Improper Authentication
|
CVE-2019-9497
|
2024-11-21 13:51 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211576
|
7.5 |
HIGH
Network
|
w1.fi fedoraproject
|
hostapd wpa_supplicant fedora
|
An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE confirm message when in hostapd/AP mode. All version o…
|
CWE-287
Improper Authentication
|
CVE-2019-9496
|
2024-11-21 13:51 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211577
|
3.7 |
LOW
Network
|
w1.fi fedoraproject opensuse debian synology freebsd
|
hostapd wpa_supplicant fedora leap backports_sle debian_linux radius_server router_manager freebsd
|
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD suppo…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-9495
|
2024-11-21 13:51 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211578
|
5.9 |
MEDIUM
Network
|
w1.fi fedoraproject opensuse synology freebsd
|
hostapd wpa_supplicant fedora leap backports_sle radius_server router_manager freebsd
|
The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-9494
|
2024-11-21 13:51 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211579
|
9.8 |
CRITICAL
Network
|
solideos
|
architectural_information_system
|
Architectural Information System 1.0 and earlier versions have a Stack-based buffer overflow, allows remote attackers to execute arbitrary code.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9134
|
2024-11-21 13:51 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211580
|
5.5 |
MEDIUM
Local
|
kmplayer fedoraproject
|
kmplayer fedora
|
When processing subtitles format media file, KMPlayer version 2018.12.24.14 or lower doesn't check object size correctly, which leads to integer underflow then to memory out-of-bound read/write. An a…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2019-9133
|
2024-11-21 13:51 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|