|
218911
|
6.8 |
MEDIUM
Physics
|
vmware
|
fusion workstation esxi
|
VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.x before 14.1.7), Fusion (11.x before 11.0.3, 10.x before 1…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2019-5518
|
2024-11-21 13:45 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218912
|
9.8 |
CRITICAL
Network
|
vmware
|
vcloud_director
|
VMware vCloud Director for Service Providers 9.5.x prior to 9.5.0.3 update resolves a Remote Session Hijack vulnerability in the Tenant and Provider Portals. Successful exploitation of this issue may…
|
CWE-384
Session Fixation
|
CVE-2019-5523
|
2024-11-21 13:45 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218913
|
9.8 |
CRITICAL
Network
|
overit
|
geocall
|
An issue was discovered in OverIT Geocall 6.3 before build 2:346977. An unauthenticated servlet allows an attacker to obtain a cookie of an authenticated user, and login to the web application.
|
NVD-CWE-noinfo
|
CVE-2019-5891
|
2024-11-21 13:45 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218914
|
8.8 |
HIGH
Network
|
overit
|
geocall
|
An issue was discovered in OverIT Geocall 6.3 before build 2:346977. Weak authentication and session management allows an authenticated user to obtain access to the Administrative control panel and e…
|
CWE-287
Improper Authentication
|
CVE-2019-5890
|
2024-11-21 13:45 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218915
|
7.5 |
HIGH
Network
|
overit
|
geocall
|
An log-management directory traversal issue was discovered in OverIT Geocall 6.3 before build 2:346977.
|
CWE-22
Path Traversal
|
CVE-2019-5889
|
2024-11-21 13:45 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218916
|
6.1 |
MEDIUM
Network
|
overit
|
geocall
|
Multiple XSS vulnerabilities were discovered in OverIT Geocall 6.3 before build 2:346977.
|
CWE-79
Cross-site Scripting
|
CVE-2019-5888
|
2024-11-21 13:45 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218917
|
7.5 |
HIGH
Network
|
nodejs opensuse
|
node.js leap
|
Keep-alive HTTP and HTTPS connections can remain open and inactive for up to 2 minutes in Node.js 6.16.0 and earlier. Node.js 8.0.0 introduced a dedicated server.keepAliveTimeout which defaults to 5 …
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-5739
|
2024-11-21 13:45 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218918
|
7.5 |
HIGH
Network
|
nodejs opensuse
|
node.js leap
|
In Node.js including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1, an attacker can cause a Denial of Service (DoS) by establishing an HTTP or HTTPS connection in…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-5737
|
2024-11-21 13:45 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218919
|
7.0 |
HIGH
Local
|
nvidia
|
geforce_experience
|
NVIDIA GeForce Experience before 3.18 contains a vulnerability when ShadowPlay or GameStream is enabled. When an attacker has access to the system and creates a hard link, the software does not check…
|
CWE-59
Link Following
|
CVE-2019-5674
|
2024-11-21 13:45 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218920
|
7.5 |
HIGH
Network
|
weban
|
an
|
Directory traversal vulnerability in 'an' App for iOS Version 3.2.0 and earlier allows remote attackers to read arbitrary files via unspecified vectors.
|
CWE-22
Path Traversal
|
CVE-2019-5927
|
2024-11-21 13:45 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|