|
219141
|
6.1 |
MEDIUM
Physics
|
nextcloud
|
nextcloud
|
Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and switching to the Nextcloud file provider.
|
CWE-287
Improper Authentication
|
CVE-2019-5453
|
2024-11-21 13:44 |
2019-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219142
|
2.4 |
LOW
Physics
|
nextcloud
|
nextcloud
|
Bypass lock protection in the Nextcloud Android app prior to version 3.6.2 causes leaking of thumbnails when requesting the Android content provider although the lock protection was not solved.
|
NVD-CWE-Other
|
CVE-2019-5452
|
2024-11-21 13:44 |
2019-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219143
|
4.6 |
MEDIUM
Physics
|
nextcloud
|
nextcloud_server
|
Bypass lock protection in the Nextcloud Android app prior to version 3.6.1 allows accessing the files when repeatedly opening and closing the app in a very short time.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-5451
|
2024-11-21 13:44 |
2019-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219144
|
6.8 |
MEDIUM
Physics
|
nextcloud
|
nextcloud
|
Improper sanitization of HTML in directory names in the Nextcloud Android app prior to version 3.7.0 allowed to style the directory name in the header bar when using basic HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2019-5450
|
2024-11-21 13:44 |
2019-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219145
|
4.3 |
MEDIUM
Network
|
nextcloud
|
nextcloud_server
|
A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidential or private events.
|
CWE-862
Missing Authorization
|
CVE-2019-5449
|
2024-11-21 13:44 |
2019-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219146
|
8.1 |
HIGH
Network
|
yarnpkg
|
yarn
|
Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-5448
|
2024-11-21 13:44 |
2019-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219147
|
5.5 |
MEDIUM
Local
|
huawei
|
honor_magic_2_firmware
|
There is an information disclosure vulnerability on Secure Input of certain Huawei smartphones in Versions earlier than Tony-AL00B 9.1.0.216(C00E214R2P1). The Secure Input does not properly limit cer…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-5222
|
2024-11-21 13:44 |
2019-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219148
|
5.3 |
MEDIUM
Network
|
http-file-server_project
|
http-file-server
|
A path traversal vulnerability in <= v0.2.6 of http-file-server npm module allows attackers to list files in arbitrary folders.
|
CWE-22
Path Traversal
|
CVE-2019-5447
|
2024-11-21 13:44 |
2019-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219149
|
7.2 |
HIGH
Network
|
ui
|
edgeswitch_firmware
|
Command Injection in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to execute commands as root.
|
CWE-77
Command Injection
|
CVE-2019-5446
|
2024-11-21 13:44 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219150
|
4.9 |
MEDIUM
Network
|
ui
|
edgeswitch_firmware
|
DoS in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to Crash the SSH CLI interface by using crafted commands.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-5445
|
2024-11-21 13:44 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|