|
213461
|
4.3 |
MEDIUM
Network
|
kaspersky
|
total_security anti-virus internet_security free_anti-virus small_office_security
|
Information Disclosure in Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security versions up to 2019 could potentially disclose unique Product ID by forcing victim to visit a spe…
|
CWE-200
Information Exposure
|
CVE-2019-8286
|
2024-11-21 13:49 |
2019-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213462
|
9.8 |
CRITICAL
Network
|
checkpoint
|
jumbo_hotfix_for_endpoint_security_server endpoint_security_server_package smartconsole_for_endpoint_security_server endpoint_security_clients remote_access_clients capsule_docs_standa…
|
Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executabl…
|
CWE-428
Unquoted Search Path or Element
|
CVE-2019-8459
|
2024-11-21 13:49 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213463
|
4.4 |
MEDIUM
Network
|
checkpoint
|
endpoint_security_clients remote_access_clients capsule_docs
|
Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with adm…
|
NVD-CWE-noinfo
|
CVE-2019-8458
|
2024-11-21 13:49 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213464
|
7.5 |
HIGH
Network
|
rubygems debian opensuse
|
rubygems debian_linux leap
|
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is. Therefore, if the API side modifies the response…
|
CWE-74
Injection
|
CVE-2019-8323
|
2024-11-21 13:49 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213465
|
7.5 |
HIGH
Network
|
rubygems debian opensuse
|
rubygems debian_linux leap
|
An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape seque…
|
CWE-74
Injection
|
CVE-2019-8322
|
2024-11-21 13:49 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213466
|
7.5 |
HIGH
Network
|
rubygems debian opensuse
|
rubygems debian_linux leap
|
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteraction#verbose calls say without escaping, escape sequence injection is possible.
|
CWE-88
Argument Injection
|
CVE-2019-8321
|
2024-11-21 13:49 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213467
|
7.5 |
HIGH
Network
|
rubygems opensuse debian
|
rubygems leap debian_linux
|
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause…
|
CWE-74
Injection
|
CVE-2019-8325
|
2024-11-21 13:49 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213468
|
8.8 |
HIGH
Network
|
rubygems debian opensuse redhat
|
rubygems debian_linux leap enterprise_linux
|
An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of …
|
CWE-94
Code Injection
|
CVE-2019-8324
|
2024-11-21 13:49 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213469
|
6.5 |
MEDIUM
Network
|
gemalto
|
sentinel_ldk
|
Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag. This allows malicious javascript to steal it.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-8283
|
2024-11-21 13:49 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213470
|
5.3 |
MEDIUM
Network
|
gemalto
|
sentinel_ldk
|
Gemalto Admin Control Center, all versions prior to 7.92, uses cleartext HTTP to communicate with www3.safenet-inc.com to obtain language packs. This allows attacker to do man-in-the-middle (MITM) at…
|
CWE-346
Origin Validation Error
|
CVE-2019-8282
|
2024-11-21 13:49 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|