|
219631
|
7.8 |
HIGH
Local
|
dell
|
supportassist_for_home_pcs supportassist_for_business_pcs
|
Dell SupportAssist for Business PCs version 2.0 and Dell SupportAssist for Home PCs version 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, and 3.2.1 contain an Improper Privilege Management V…
|
CWE-269
Improper Privilege Management
|
CVE-2019-3735
|
2024-11-21 13:42 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219632
|
8.8 |
HIGH
Network
|
pivotal_software
|
cloud_foundry_uaa-release
|
Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending “unknown.org” to a user's email address when one is not provided and the user name does not contain an @ character. This domain is…
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2019-3787
|
2024-11-21 13:42 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219633
|
7.5 |
HIGH
Network
|
dell
|
avamar_data_migration_enabler_web_interface
|
Dell EMC Avamar ADMe Web Interface 1.0.50 and 1.0.51 are affected by an LFI vulnerability which may allow a malicious user to download arbitrary files from the affected system by sending a specially …
|
CWE-22
Path Traversal
|
CVE-2019-3737
|
2024-11-21 13:42 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219634
|
9.8 |
CRITICAL
Network
|
advantech
|
webaccess
|
Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbitrary code by sending a crafted IOCTL 81024 RPC call.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-3954
|
2024-11-21 13:42 |
2019-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219635
|
7.8 |
HIGH
Local
|
linux redhat
|
linux_kernel enterprise_linux_server_aus enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw for a privilege escalation or for a system crash and a denia…
|
-
|
CVE-2019-3896
|
2024-11-21 13:42 |
2019-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219636
|
9.8 |
CRITICAL
Network
|
advantech
|
webaccess
|
Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbitrary code by sending a crafted IOCTL 10012 RPC call.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-3953
|
2024-11-21 13:42 |
2019-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219637
|
9.8 |
CRITICAL
Network
|
fujielectric
|
v-server
|
Fuji Electric V-Server before 6.0.33.0 stores database credentials in project files as plaintext. An attacker that can gain access to the project file can recover the database credentials and gain ac…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-3947
|
2024-11-21 13:42 |
2019-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219638
|
7.5 |
HIGH
Network
|
fujielectric
|
v-server
|
Fuji Electric V-Server before 6.0.33.0 is vulnerable to denial of service via a crafted UDP message sent to port 8005. An unauthenticated, remote attacker can crash vserver.exe due to an integer over…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-3946
|
2024-11-21 13:42 |
2019-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219639
|
9.8 |
CRITICAL
Network
|
redhat netapp
|
undertow virtualization virtualization_host jboss_data_grid openshift_application_runtimes active_iq_unified_manager
|
A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchan…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-3888
|
2024-11-21 13:42 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219640
|
9.0 |
CRITICAL
Network
|
redhat
|
jboss_enterprise_application_platform single_sign-on
|
It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An attacker could use this flaw to send a URL to achieve…
|
CWE-79
Cross-site Scripting
|
CVE-2019-3873
|
2024-11-21 13:42 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|