|
219861
|
7.1 |
HIGH
Local
|
mcafee
|
total_protection
|
Exploitation of Privilege/Trust vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0.R18 allows local users to bypass product self-protection, tamper with policies…
|
NVD-CWE-noinfo
|
CVE-2019-3593
|
2024-11-21 13:42 |
2019-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219862
|
3.3 |
LOW
Local
|
redhat debian
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_eus enterprise_linux_server_aus openshift_container_platform debian_linux
|
A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c does not free the memory allocated by set_i…
|
-
|
CVE-2019-3815
|
2024-11-21 13:42 |
2019-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219863
|
4.4 |
MEDIUM
Local
|
linux debian canonical opensuse
|
linux_kernel debian_linux ubuntu_linux leap
|
A flaw was found in the Linux kernel in the function hid_debug_events_read() in drivers/hid/hid-debug.c file which may enter an infinite loop with certain parameters passed from a userspace. A local …
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-3819
|
2024-11-21 13:42 |
2019-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219864
|
6.5 |
MEDIUM
Local
|
mcafee
|
total_protection
|
DLL Search Order Hijacking vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0.18 allows local users to execute arbitrary code via execution from a compromised fo…
|
CWE-426
Untrusted Search Path
|
CVE-2019-3587
|
2024-11-21 13:42 |
2019-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219865
|
6.0 |
MEDIUM
Local
|
mcafee
|
mvision_endpoint
|
Exploitation of Authentication vulnerability in MVision Endpoint in McAfee MVision Endpoint Prior to 1811 Update 1 (18.11.31.62) allows authenticated administrator users --> administrators to Remove …
|
CWE-287
Improper Authentication
|
CVE-2019-3584
|
2024-11-21 13:42 |
2019-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219866
|
9.8 |
CRITICAL
Network
|
pivotal_software
|
spring_batch
|
Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
|
CWE-611
XXE
|
CVE-2019-3774
|
2024-11-21 13:42 |
2019-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219867
|
9.8 |
CRITICAL
Network
|
pivotal_software oracle
|
spring_web_services flexcube_private_banking financial_services_analytical_applications_infrastructure
|
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted source…
|
CWE-611
XXE
|
CVE-2019-3773
|
2024-11-21 13:42 |
2019-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219868
|
9.8 |
CRITICAL
Network
|
vmware oracle
|
spring_integration retail_customer_management_and_segmentation_foundation
|
Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) …
|
CWE-611
XXE
|
CVE-2019-3772
|
2024-11-21 13:42 |
2019-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219869
|
9.1 |
CRITICAL
Network
|
crestron
|
airmedia_am-100_firmware
|
Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script. Unauthenticated remote users can use the bypass to access some administrato…
|
NVD-CWE-noinfo
|
CVE-2019-3910
|
2024-11-21 13:42 |
2019-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219870
|
9.8 |
CRITICAL
Network
|
identicard
|
premisys_id
|
Premisys Identicard version 3.1.190 database uses default credentials. Users are unable to change the credentials without vendor intervention.
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2019-3909
|
2024-11-21 13:42 |
2019-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|