|
219151
|
7.8 |
HIGH
Local
|
bluecats
|
bc_reveal
|
The iOS mobile application BlueCats Reveal before 5.14 stores the username and password in the app cache as base64 encoded strings, i.e. clear text. These persist in the cache even if the user logs o…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-5627
|
2024-11-21 13:45 |
2019-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219152
|
7.8 |
HIGH
Local
|
bluecats
|
bluecats_reveal
|
The Android mobile application BlueCats Reveal before 3.0.19 stores the username and password in a clear text file. This file persists until the user logs out or the session times out from non-usage …
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-5626
|
2024-11-21 13:45 |
2019-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219153
|
7.1 |
HIGH
Local
|
eaton
|
halo_home
|
The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear text file. This file persists until the user logs out of the application and re…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-5625
|
2024-11-21 13:45 |
2019-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219154
|
7.8 |
HIGH
Local
|
soumu
|
electronic_reception_and_examination_of_application_for_radio_licenses
|
Untrusted search path vulnerability in Electronic reception and examination of application for radio licenses Offline 1.0.9.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL …
|
CWE-426
Untrusted Search Path
|
CVE-2019-5958
|
2024-11-21 13:45 |
2019-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219155
|
7.8 |
HIGH
Local
|
soumu
|
electronic_reception_and_examination_of_application_for_radio_licenses
|
Untrusted search path vulnerability in Installer of Electronic reception and examination of application for radio licenses Online 1.0.9.0 and earlier allows an attacker to gain privileges via a Troja…
|
CWE-426
Untrusted Search Path
|
CVE-2019-5957
|
2024-11-21 13:45 |
2019-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219156
|
5.4 |
MEDIUM
Network
|
create-sd
|
create_sd
|
CREATE SD official App for Android version 1.0.2 and earlier allows remote attackers to bypass access restriction to lead a user to access an arbitrary website via vulnerable application and conduct …
|
NVD-CWE-noinfo
|
CVE-2019-5955
|
2024-11-21 13:45 |
2019-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219157
|
9.1 |
CRITICAL
Network
|
jreast
|
jr_east_japan
|
JR East Japan train operation information push notification App for Android version 1.2.4 and earlier allows remote attackers to bypass access restriction to obtain or alter the user's registered inf…
|
NVD-CWE-noinfo
|
CVE-2019-5954
|
2024-11-21 13:45 |
2019-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219158
|
9.8 |
CRITICAL
Network
|
gnu
|
wget
|
Buffer overflow in GNU Wget 1.20.1 and earlier allows remote attackers to cause a denial-of-service (DoS) or may execute an arbitrary code via unspecified vectors.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-5953
|
2024-11-21 13:45 |
2019-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219159
|
5.4 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cross-site scripting vulnerability in Cybozu Garoon 4.6.0 to 4.10.1 allows remote authenticated attackers to inject arbitrary web script or HTML via the application 'Cabinet'.
|
CWE-79
Cross-site Scripting
|
CVE-2019-5947
|
2024-11-21 13:45 |
2019-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219160
|
6.1 |
MEDIUM
Network
|
cybozu
|
garoon
|
Open redirect vulnerability in Cybozu Garoon 4.2.4 to 4.10.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the Login Screen.
|
CWE-601
Open Redirect
|
CVE-2019-5946
|
2024-11-21 13:45 |
2019-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|