|
219111
|
7.5 |
HIGH
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to caus…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-4720
|
2024-11-21 13:44 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219112
|
7.1 |
HIGH
Network
|
ibm
|
security_access_manager
|
IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sen…
|
CWE-611
XXE
|
CVE-2019-4707
|
2024-11-21 13:44 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219113
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboard which could result in disclosure of vulnerability feedback information.
|
CWE-862
Missing Authorization
|
CVE-2019-5470
|
2024-11-21 13:44 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219114
|
8.8 |
HIGH
Network
|
gitlab
|
gitlab
|
An privilege escalation issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 when Mattermost slash commands are used with a blocked account.
|
CWE-269
Improper Privilege Management
|
CVE-2019-5468
|
2024-11-21 13:44 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219115
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new merge requests endpoint to disclose label names.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-5466
|
2024-11-21 13:44 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219116
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which could result in disclosure of the newly created issue ID.
|
NVD-CWE-noinfo
|
CVE-2019-5465
|
2024-11-21 13:44 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219117
|
9.8 |
CRITICAL
Network
|
gitlab
|
gitlab
|
A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the library is utilized.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-5464
|
2024-11-21 13:44 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219118
|
8.8 |
HIGH
Network
|
gitlab
|
gitlab
|
A privilege escalation issue was discovered in GitLab CE/EE 9.0 and later when trigger tokens are not rotated once ownership of them has changed.
|
CWE-613
Insufficient Session Expiration
|
CVE-2019-5462
|
2024-11-21 13:44 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219119
|
9.0 |
CRITICAL
Network
|
amd
|
atidxx64
|
An exploitable type confusion vulnerability exists in AMD ATIDXX64.DLL driver, versions 26.20.13031.10003, 26.20.13031.15006 and 26.20.13031.18002. A specially crafted pixel shader can cause a type c…
|
CWE-843
Type Confusion
|
CVE-2019-5183
|
2024-11-21 13:44 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219120
|
8.6 |
HIGH
Network
|
amd
|
atidxx64
|
An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13003.1007. A specially crafted pixel shader can cause a denial of service. An attacker can provide a …
|
CWE-125
Out-of-bounds Read
|
CVE-2019-5147
|
2024-11-21 13:44 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|