|
219861
|
7.5 |
HIGH
Network
|
isc
|
bind
|
An error in the EDNS Client Subnet (ECS) feature for recursive resolvers can cause BIND to exit with an assertion failure when processing a response that has malformed RRSIGs. Versions affected: BIND…
|
CWE-617
Reachable Assertion
|
CVE-2019-6469
|
2024-11-21 13:46 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219862
|
7.5 |
HIGH
Network
|
isc
|
bind
|
In BIND Supported Preview Edition, an error in the nxdomain-redirect feature can occur in versions which support EDNS Client Subnet (ECS) features. In those versions which have ECS support, enabling …
|
CWE-617
Reachable Assertion
|
CVE-2019-6468
|
2024-11-21 13:46 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219863
|
5.9 |
MEDIUM
Network
|
f5 isc
|
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_access_policy_manager big-ip_application_security_manager<…
|
A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion failure in dispatch.c. Versions affected: BIND 9.11.0 -> 9.11.7, 9.12.0 -> 9.1…
|
CWE-362 CWE-617
Race Condition Reachable Assertion
|
CVE-2019-6471
|
2024-11-21 13:46 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219864
|
7.5 |
HIGH
Network
|
isc
|
bind
|
A programming error in the nxdomain-redirect feature can cause an assertion failure in query.c if the alternate namespace used by nxdomain-redirect is a descendant of a zone that is served locally. T…
|
CWE-617
Reachable Assertion
|
CVE-2019-6467
|
2024-11-21 13:46 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219865
|
5.3 |
MEDIUM
Network
|
isc redhat
|
bind enterprise_linux
|
Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P2, 9.12.0 -> 9.12.…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-6465
|
2024-11-21 13:46 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219866
|
7.5 |
HIGH
Network
|
lenovo
|
system_update
|
A denial of service vulnerability was reported in Lenovo System Update versions prior to 5.07.0088 that could allow configuration files to be written to non-standard locations.
|
NVD-CWE-noinfo
|
CVE-2019-6175
|
2024-11-21 13:46 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219867
|
7.5 |
HIGH
Network
|
lenovo
|
cp_storage_block_firmware
|
An internal product security audit discovered a session handling vulnerability in the web interface of ThinkAgile CP-SB (Storage Block) BMC in firmware versions prior to 1908.M. This vulnerability al…
|
CWE-384
Session Fixation
|
CVE-2019-6161
|
2024-11-21 13:46 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219868
|
5.3 |
MEDIUM
Network
|
f5
|
big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_access_policy_manager big-ip_application_security_manager big-ip_policy_enforcement_man…
|
On versions 13.0.0-13.1.0.1, 12.1.0-12.1.4.1, 11.6.1-11.6.4, and 11.5.1-11.5.9, BIG-IP platforms where AVR, ASM, APM, PEM, AFM, and/or AAM is provisioned may leak sensitive data.
|
NVD-CWE-noinfo
|
CVE-2019-6655
|
2024-11-21 13:46 |
2019-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219869
|
7.5 |
HIGH
Network
|
f5
|
big-ip_access_policy_manager big-ip_access_policy_manager_client
|
BIG-IP APM Edge Client before version 7.1.8 (7180.2019.508.705) logs the full apm session ID in the log files. Vulnerable versions of the client are bundled with BIG-IP APM versions 15.0.0-15.0.1, 14…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-6656
|
2024-11-21 13:46 |
2019-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219870
|
5.4 |
MEDIUM
Network
|
f5
|
big-iq_centralized_management
|
There is a Stored Cross Site Scripting vulnerability in the undisclosed page of a BIG-IQ 6.0.0-6.1.0 or 5.2.0-5.4.0 system. The attack can be stored by users granted the Device Manager and Administra…
|
CWE-79
Cross-site Scripting
|
CVE-2019-6653
|
2024-11-21 13:46 |
2019-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|