|
222801
|
8.8 |
HIGH
Network
|
proofpoint
|
enterprise_protection
|
A file-extension filtering vulnerability in Proofpoint Enterprise Protection (PPS / PoD), in the unpatched versions of PPS through 8.9.22 and 8.14.2 respectively, allows attackers to bypass protectio…
|
NVD-CWE-Other
|
CVE-2019-19680
|
2024-11-21 13:35 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222802
|
7.5 |
HIGH
Network
|
schedmd opensuse debian
|
slurm leap debian_linux
|
SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges.
|
CWE-269
Improper Privilege Management
|
CVE-2019-19728
|
2024-11-21 13:35 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222803
|
5.5 |
MEDIUM
Local
|
schedmd opensuse
|
slurm leap
|
SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 has weak slurmdbd.conf permissions.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-19727
|
2024-11-21 13:35 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222804
|
5.9 |
MEDIUM
Network
|
mitel
|
sip-dect_firmware
|
An encryption key vulnerability on Mitel SIP-DECT wireless devices 8.0 and 8.1 could allow an attacker to launch a man-in-the-middle attack. A successful exploit may allow the attacker to intercept s…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-19891
|
2024-11-21 13:35 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222805
|
5.5 |
MEDIUM
Local
|
gonitro
|
nitropdf
|
The JBIG2Globals library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x90ec NULL Pointer Dereference via crafted Unicode content.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-19819
|
2024-11-21 13:35 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222806
|
5.5 |
MEDIUM
Local
|
gonitro
|
nitro_free_pdf_reader
|
The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x2e8a Out-of-Bounds Read via crafted Unicode content.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-19817
|
2024-11-21 13:35 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222807
|
7.8 |
HIGH
Local
|
kyrol
|
internet_security
|
An invalid pointer vulnerability in IOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an attacker to achieve privilege escalation, denial-of-service, and code execution…
|
CWE-763
Release of Invalid Pointer or Reference
|
CVE-2019-19820
|
2024-11-21 13:35 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222808
|
7.5 |
HIGH
Network
|
python debian fedoraproject canonical
|
pillow debian_linux fedora ubuntu_linux
|
There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-19911
|
2024-11-21 13:35 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222809
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by the Elasticsearch int…
|
NVD-CWE-noinfo
|
CVE-2019-19629
|
2024-11-21 13:35 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222810
|
9.8 |
CRITICAL
Network
|
gitlab
|
gitlab
|
In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities u…
|
CWE-22
Path Traversal
|
CVE-2019-19628
|
2024-11-21 13:35 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|