|
219171
|
6.5 |
MEDIUM
Network
|
mcafee
|
enterprise_security_manager
|
Application protection bypass vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows unauthenticated user to impersonate system users via specially craft…
|
NVD-CWE-noinfo
|
CVE-2019-3629
|
2024-11-21 13:42 |
2019-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219172
|
8.8 |
HIGH
Network
|
mcafee
|
enterprise_security_manager
|
Privilege escalation in McAfee Enterprise Security Manager (ESM) 11.x prior to 11.2.0 allows authenticated user to gain access to a core system component via incorrect access control.
|
NVD-CWE-noinfo
|
CVE-2019-3628
|
2024-11-21 13:42 |
2019-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219173
|
7.5 |
HIGH
Network
|
facebook
|
hhvm
|
HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct access to the application, which could result in in…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2019-3569
|
2024-11-21 13:42 |
2019-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219174
|
6.1 |
MEDIUM
Network
|
tenable
|
nessus
|
Nessus versions 8.4.0 and earlier were found to contain a reflected XSS vulnerability due to improper validation of user-supplied input. An unauthenticated, remote attacker could potentially exploit …
|
CWE-79
Cross-site Scripting
|
CVE-2019-3961
|
2024-11-21 13:42 |
2019-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219175
|
7.8 |
HIGH
Local
|
dell
|
supportassist_for_home_pcs supportassist_for_business_pcs
|
Dell SupportAssist for Business PCs version 2.0 and Dell SupportAssist for Home PCs version 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, and 3.2.1 contain an Improper Privilege Management V…
|
CWE-269
Improper Privilege Management
|
CVE-2019-3735
|
2024-11-21 13:42 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219176
|
8.8 |
HIGH
Network
|
pivotal_software
|
cloud_foundry_uaa-release
|
Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending “unknown.org” to a user's email address when one is not provided and the user name does not contain an @ character. This domain is…
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2019-3787
|
2024-11-21 13:42 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219177
|
7.5 |
HIGH
Network
|
dell
|
avamar_data_migration_enabler_web_interface
|
Dell EMC Avamar ADMe Web Interface 1.0.50 and 1.0.51 are affected by an LFI vulnerability which may allow a malicious user to download arbitrary files from the affected system by sending a specially …
|
CWE-22
Path Traversal
|
CVE-2019-3737
|
2024-11-21 13:42 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219178
|
9.8 |
CRITICAL
Network
|
advantech
|
webaccess
|
Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbitrary code by sending a crafted IOCTL 81024 RPC call.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-3954
|
2024-11-21 13:42 |
2019-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219179
|
7.8 |
HIGH
Local
|
linux redhat
|
linux_kernel enterprise_linux_server_aus enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw for a privilege escalation or for a system crash and a denia…
|
-
|
CVE-2019-3896
|
2024-11-21 13:42 |
2019-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219180
|
9.8 |
CRITICAL
Network
|
advantech
|
webaccess
|
Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbitrary code by sending a crafted IOCTL 10012 RPC call.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-3953
|
2024-11-21 13:42 |
2019-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|