|
222631
|
7.5 |
HIGH
Network
|
dell
|
avamar_data_migration_enabler_web_interface
|
Dell EMC Avamar ADMe Web Interface 1.0.50 and 1.0.51 are affected by an LFI vulnerability which may allow a malicious user to download arbitrary files from the affected system by sending a specially …
|
CWE-22
Path Traversal
|
CVE-2019-3737
|
2024-11-21 13:42 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222632
|
9.8 |
CRITICAL
Network
|
advantech
|
webaccess
|
Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbitrary code by sending a crafted IOCTL 81024 RPC call.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-3954
|
2024-11-21 13:42 |
2019-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222633
|
7.8 |
HIGH
Local
|
linux redhat
|
linux_kernel enterprise_linux_server_aus enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw for a privilege escalation or for a system crash and a denia…
|
-
|
CVE-2019-3896
|
2024-11-21 13:42 |
2019-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222634
|
9.8 |
CRITICAL
Network
|
advantech
|
webaccess
|
Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbitrary code by sending a crafted IOCTL 10012 RPC call.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-3953
|
2024-11-21 13:42 |
2019-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222635
|
9.8 |
CRITICAL
Network
|
fujielectric
|
v-server
|
Fuji Electric V-Server before 6.0.33.0 stores database credentials in project files as plaintext. An attacker that can gain access to the project file can recover the database credentials and gain ac…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-3947
|
2024-11-21 13:42 |
2019-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222636
|
7.5 |
HIGH
Network
|
fujielectric
|
v-server
|
Fuji Electric V-Server before 6.0.33.0 is vulnerable to denial of service via a crafted UDP message sent to port 8005. An unauthenticated, remote attacker can crash vserver.exe due to an integer over…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-3946
|
2024-11-21 13:42 |
2019-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222637
|
9.8 |
CRITICAL
Network
|
redhat netapp
|
undertow virtualization virtualization_host jboss_data_grid openshift_application_runtimes active_iq_unified_manager
|
A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchan…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-3888
|
2024-11-21 13:42 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222638
|
9.0 |
CRITICAL
Network
|
redhat
|
jboss_enterprise_application_platform single_sign-on
|
It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An attacker could use this flaw to send a URL to achieve…
|
CWE-79
Cross-site Scripting
|
CVE-2019-3873
|
2024-11-21 13:42 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222639
|
5.4 |
MEDIUM
Network
|
redhat
|
jboss_enterprise_application_platform single_sign-on
|
It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. An attacker could use this to send a malicious scr…
|
CWE-79
Cross-site Scripting
|
CVE-2019-3872
|
2024-11-21 13:42 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222640
|
4.8 |
MEDIUM
Network
|
redhat
|
single_sign-on keycloak
|
A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRL, where the CRL list can be obtained from the URL provided …
|
CWE-295
Improper Certificate Validation
|
CVE-2019-3875
|
2024-11-21 13:42 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|