|
219031
|
9.8 |
CRITICAL
Network
|
advantech
|
webaccess
|
Advantech WebAccess before 8.4.3 allows unauthenticated remote attackers to execute arbitrary code or cause a denial of service (memory corruption) due to a stack-based buffer overflow when handling …
|
CWE-787
Out-of-bounds Write
|
CVE-2019-3951
|
2024-11-21 13:42 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219032
|
7.8 |
HIGH
Local
|
mcafee
|
techcheck
|
DLL Search Order Hijacking vulnerability in the Microsoft Windows client in McAfee Tech Check 3.0.0.17 and earlier allows local users to execute arbitrary code via the local folder placed there by an…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-3667
|
2024-11-21 13:42 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219033
|
7.8 |
HIGH
Local
|
opensuse
|
leap
|
The chkstat tool in the permissions package followed symlinks before commit a9e1d26cd49ef9ee0c2060c859321128a6dd4230 (please also check the additional hardenings after this fix). This allowed local a…
|
-
|
CVE-2019-3690
|
2024-11-21 13:42 |
2019-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219034
|
5.5 |
MEDIUM
Local
|
dell
|
command_update
|
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to de…
|
CWE-59
Link Following
|
CVE-2019-3750
|
2024-11-21 13:42 |
2019-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219035
|
5.5 |
MEDIUM
Local
|
dell
|
command_update
|
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to de…
|
CWE-59
Link Following
|
CVE-2019-3749
|
2024-11-21 13:42 |
2019-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219036
|
6.5 |
MEDIUM
Network
|
mcafee
|
webadvisor
|
API Abuse/Misuse vulnerability in the web interface in McAfee Web Advisor (WA) prior to 4.1.1.48 allows remote unauthenticated attacker to allow the browser to navigate to restricted websites via a c…
|
NVD-CWE-Other
|
CVE-2019-3666
|
2024-11-21 13:42 |
2019-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219037
|
6.5 |
MEDIUM
Network
|
mcafee
|
webadvisor
|
Code Injection vulnerability in the web interface in McAfee Web Advisor (WA) prior to 4.1.1.48 allows remote unauthenticated attacker to allow the browser to render a website which Web Advisor would …
|
CWE-94
Code Injection
|
CVE-2019-3665
|
2024-11-21 13:42 |
2019-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219038
|
8.6 |
HIGH
Local
|
mcafee
|
client_proxy
|
Authentication Bypass vulnerability in the Microsoft Windows client in McAfee Client Proxy (MCP) prior to 3.0.0 allows local user to bypass scanning of web traffic and gain access to blocked sites fo…
|
CWE-287
Improper Authentication
|
CVE-2019-3654
|
2024-11-21 13:42 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219039
|
6.5 |
MEDIUM
Network
|
zte
|
zxcdn_iamweb_firmware
|
The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a configuration error vulnerability. An attacker could directly access the management portal in HTTP, resulting in users’ informatio…
|
NVD-CWE-noinfo
|
CVE-2019-3428
|
2024-11-21 13:42 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219040
|
7.2 |
HIGH
Network
|
zte
|
zxcdn_iamweb_firmware
|
The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a code injection vulnerability. An attacker could exploit the vulnerability to inject malicious code into the management page, resul…
|
CWE-94
Code Injection
|
CVE-2019-3427
|
2024-11-21 13:42 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|