|
222611
|
7.8 |
HIGH
Local
|
aviatrix
|
vpn_client
|
Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allow a local attacker to execute arbitrary code by gaining elevated privileges thr…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-17388
|
2024-11-21 13:32 |
2019-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222612
|
7.8 |
HIGH
Local
|
aviatrix
|
vpn_client
|
An authentication flaw in the AVPNC_RP service in Aviatrix VPN Client through 2.2.10 allows an attacker to gain elevated privileges through arbitrary code execution on Windows, Linux, and macOS.
|
NVD-CWE-noinfo
|
CVE-2019-17387
|
2024-11-21 13:32 |
2019-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222613
|
7.5 |
HIGH
Network
|
otrs
|
otrs
|
Improper Check for filenames with overly long extensions in PostMaster (sending in email) or uploading files (e.g. attaching files to mails) of ((OTRS)) Community Edition and OTRS allows an remote at…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-18180
|
2024-11-21 13:32 |
2019-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222614
|
7.8 |
HIGH
Local
|
paloaltonetworks
|
pan-os
|
An improper authentication check in Palo Alto Networks PAN-OS may allow an authenticated low privileged non-superuser custom role user to elevate privileges and become superuser. This issue affects P…
|
CWE-287
Improper Authentication
|
CVE-2019-17437
|
2024-11-21 13:32 |
2019-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222615
|
7.5 |
HIGH
Network
|
apache
|
olingo
|
The AsyncResponseWrapperImpl class in Apache Olingo versions 4.0.0 to 4.6.0 reads the Retry-After header and passes it to the Thread.sleep() method without any check. If a malicious server returns a …
|
CWE-20
Improper Input Validation
|
CVE-2019-17555
|
2024-11-21 13:32 |
2019-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222616
|
9.8 |
CRITICAL
Network
|
apache
|
olingo
|
Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being deserialized. If an attacker can feed malicious me…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-17556
|
2024-11-21 13:32 |
2019-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222617
|
5.5 |
MEDIUM
Local
|
apache
|
olingo
|
The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Request with content type "application/xml", which tri…
|
CWE-611
XXE
|
CVE-2019-17554
|
2024-11-21 13:32 |
2019-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222618
|
7.8 |
HIGH
Local
|
gnu netapp oracle
|
bash solidfire hci_management_node oncommand_unified_manager communications_cloud_native_core_policy
|
An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run with its effective UID not equal to its real UID, it will drop privileges by setti…
|
CWE-273
Improper Check for Dropped Privileges
|
CVE-2019-18276
|
2024-11-21 13:32 |
2019-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222619
|
10.0 |
CRITICAL
Network
|
hitachienergy
|
relion_670_firmware
|
An attacker could use specially crafted paths in a specific request to read or delete files from Relion 670 Series (versions 1p1r26, 1.2.3.17, 2.0.0.10, RES670 2.0.0.4, 2.1.0.1, and prior) outside th…
|
CWE-22
Path Traversal
|
CVE-2019-18253
|
2024-11-21 13:32 |
2019-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222620
|
7.5 |
HIGH
Network
|
hitachienergy
|
relion_650_firmware relion_670_firmware
|
An attacker may use a specially crafted message to force Relion 650 series (versions 1.3.0.5 and prior) or Relion 670 series (versions 1.2.3.18, 2.0.0.11, 2.1.0.1 and prior) to reboot, which could ca…
|
CWE-20
Improper Input Validation
|
CVE-2019-18247
|
2024-11-21 13:32 |
2019-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|