|
212541
|
7.8 |
HIGH
Local
|
foxitsoftware
|
foxit_reader
|
A Local Privilege Escalation in libqcocoa.dylib in Foxit Reader 3.1.0.0111 on macOS has been discovered due to an incorrect permission set.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-8342
|
2024-11-21 13:49 |
2019-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212542
|
6.8 |
MEDIUM
Physics
|
simple
|
better_banking
|
The Simple - Better Banking application 2.45.0 through 2.45.3 (fixed in 2.46.0) for Android was affected by an information disclosure vulnerability that leaked the user's password to the keyboard aut…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-8350
|
2024-11-21 13:49 |
2019-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212543
|
8.8 |
HIGH
Network
|
kaspersky
|
antivirus_engine
|
Kaspersky Lab Antivirus Engine version before 04.apr.2019 has a heap-based buffer overflow vulnerability that potentially allow arbitrary code execution
|
CWE-787
Out-of-bounds Write
|
CVE-2019-8285
|
2024-11-21 13:49 |
2019-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212544
|
9.8 |
CRITICAL
Network
|
barni
|
master_ip_camera01_firmware
|
MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component.
|
NVD-CWE-noinfo
|
CVE-2019-8387
|
2024-11-21 13:49 |
2019-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212545
|
6.1 |
MEDIUM
Network
|
htmly
|
htmly
|
Multiple cross-site scripting (XSS) vulnerabilities in HTMLy 2.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) destination parameter to delete feature; the (2) destinati…
|
CWE-79
Cross-site Scripting
|
CVE-2019-8349
|
2024-11-21 13:49 |
2019-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212546
|
7.0 |
HIGH
Local
|
checkpoint
|
endpoint_security
|
A local attacker can create a hard-link between a file to which the Check Point Endpoint Security client for Windows before E80.96 writes and another BAT file, then by impersonating the WPAD server, …
|
CWE-59
Link Following
|
CVE-2019-8454
|
2024-11-21 13:49 |
2019-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212547
|
7.8 |
HIGH
Local
|
checkpoint
|
zonealarm endpoint_security
|
A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security client for Windows before E80.96 to any file on the system will get its permission c…
|
CWE-59
Link Following
|
CVE-2019-8452
|
2024-11-21 13:49 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212548
|
7.1 |
HIGH
Local
|
checkpoint
|
zonealarm
|
A hard-link created from the log file of Check Point ZoneAlarm up to 15.4.062 to any file on the system will get its permission changed so that all users can access that linked file. Doing this on fi…
|
CWE-59
Link Following
|
CVE-2019-8455
|
2024-11-21 13:49 |
2019-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212549
|
5.5 |
MEDIUM
Local
|
checkpoint
|
zonealarm
|
Some of the DLLs loaded by Check Point ZoneAlarm up to 15.4.062 are taken from directories where all users have write permissions. This can allow a local attacker to replace a DLL file with a malicio…
|
CWE-426
Untrusted Search Path
|
CVE-2019-8453
|
2024-11-21 13:49 |
2019-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212550
|
5.9 |
MEDIUM
Network
|
checkpoint
|
ipsec_vpn
|
Check Point IKEv2 IPsec VPN up to R80.30, in some less common conditions, may allow an attacker with knowledge of the internal configuration and setup to successfully connect to a site-to-site VPN se…
|
NVD-CWE-noinfo
|
CVE-2019-8456
|
2024-11-21 13:49 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|