|
212521
|
4.4 |
MEDIUM
Network
|
checkpoint
|
endpoint_security_clients remote_access_clients capsule_docs
|
Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with adm…
|
NVD-CWE-noinfo
|
CVE-2019-8458
|
2024-11-21 13:49 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212522
|
7.5 |
HIGH
Network
|
rubygems debian opensuse
|
rubygems debian_linux leap
|
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is. Therefore, if the API side modifies the response…
|
CWE-74
Injection
|
CVE-2019-8323
|
2024-11-21 13:49 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212523
|
7.5 |
HIGH
Network
|
rubygems debian opensuse
|
rubygems debian_linux leap
|
An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape seque…
|
CWE-74
Injection
|
CVE-2019-8322
|
2024-11-21 13:49 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212524
|
7.5 |
HIGH
Network
|
rubygems debian opensuse
|
rubygems debian_linux leap
|
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteraction#verbose calls say without escaping, escape sequence injection is possible.
|
CWE-88
Argument Injection
|
CVE-2019-8321
|
2024-11-21 13:49 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212525
|
7.5 |
HIGH
Network
|
rubygems opensuse debian
|
rubygems leap debian_linux
|
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause…
|
CWE-74
Injection
|
CVE-2019-8325
|
2024-11-21 13:49 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212526
|
8.8 |
HIGH
Network
|
rubygems debian opensuse redhat
|
rubygems debian_linux leap enterprise_linux
|
An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of …
|
CWE-94
Code Injection
|
CVE-2019-8324
|
2024-11-21 13:49 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212527
|
6.5 |
MEDIUM
Network
|
gemalto
|
sentinel_ldk
|
Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag. This allows malicious javascript to steal it.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-8283
|
2024-11-21 13:49 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212528
|
5.3 |
MEDIUM
Network
|
gemalto
|
sentinel_ldk
|
Gemalto Admin Control Center, all versions prior to 7.92, uses cleartext HTTP to communicate with www3.safenet-inc.com to obtain language packs. This allows attacker to do man-in-the-middle (MITM) at…
|
CWE-346
Origin Validation Error
|
CVE-2019-8282
|
2024-11-21 13:49 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212529
|
7.4 |
HIGH
Network
|
rubygems
|
rubygems
|
A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2. Before making new directories or touching files (which now include path-checking code for symlinks), it would del…
|
CWE-22
Path Traversal
|
CVE-2019-8320
|
2024-11-21 13:49 |
2019-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212530
|
9.8 |
CRITICAL
Network
|
thomsonreuters
|
firm_central_desktop concourse_matter_room
|
An issue was discovered in Thomson Reuters Desktop Extensions 1.9.0.358. An unauthenticated directory traversal and local file inclusion vulnerability in the ThomsonReuters.Desktop.Service.exe and Th…
|
CWE-22
Path Traversal
|
CVE-2019-8385
|
2024-11-21 13:49 |
2019-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|