|
219681
|
7.5 |
HIGH
Network
|
facebook
|
thrift
|
C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2019-3552
|
2024-11-21 13:42 |
2019-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219682
|
8.8 |
HIGH
Network
|
redhat
|
wildfly jboss_enterprise_application_platform
|
It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if …
|
NVD-CWE-noinfo
|
CVE-2019-3894
|
2024-11-21 13:42 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219683
|
4.7 |
MEDIUM
Local
|
redhat
|
jboss_enterprise_application_platform wildfly
|
A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could explo…
|
CWE-269
Improper Privilege Management
|
CVE-2019-3805
|
2024-11-21 13:42 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219684
|
6.1 |
MEDIUM
Network
|
atlassian
|
jira_server
|
The labels gadget in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerabil…
|
CWE-79
Cross-site Scripting
|
CVE-2019-3400
|
2024-11-21 13:42 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219685
|
6.1 |
MEDIUM
Network
|
microfocus
|
open_enterprise_server
|
A DOM based XSS vulnerability has been identified in the Netstorage component of Open Enterprise Server (OES) allowing a remote attacker to execute javascript in the victims browser by tricking the v…
|
CWE-79
Cross-site Scripting
|
CVE-2019-3490
|
2024-11-21 13:42 |
2019-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219686
|
9.8 |
CRITICAL
Network
|
crestron
|
am-100_firmware am-101_firmware
|
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator/moderator for the web interface. An unauthenticated, remote attacker can use t…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-3939
|
2024-11-21 13:42 |
2019-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219687
|
7.8 |
HIGH
Local
|
crestron
|
am-100_firmware am-101_firmware
|
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, and other configuration options in the file generated via the "export configuration" feature. The c…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-3938
|
2024-11-21 13:42 |
2019-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219688
|
7.8 |
HIGH
Local
|
crestron
|
am-100_firmware am-101_firmware
|
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, slideshow passcode, and other configuration options in cleartext in the file /tmp/scfgdndf. A local…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2019-3937
|
2024-11-21 13:42 |
2019-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219689
|
7.5 |
HIGH
Network
|
crestron
|
am-100_firmware am-101_firmware
|
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 is vulnerable to denial of service via a crafted request to TCP port 389. The request will force the slideshow to transition int…
|
NVD-CWE-noinfo
|
CVE-2019-3936
|
2024-11-21 13:42 |
2019-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219690
|
9.1 |
CRITICAL
Network
|
crestron
|
am-100_firmware am-101_firmware
|
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to act as a moderator to a slide show via crafted HTTP POST requests to conference.cgi. A remote, unauthenticated …
|
NVD-CWE-Other
|
CVE-2019-3935
|
2024-11-21 13:42 |
2019-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|