|
212841
|
7.8 |
HIGH
Local
|
autodesk
|
fbx_software_development_kit
|
Buffer overflow vulnerability in Autodesk FBX Software Development Kit version 2019.5. A user may be tricked into opening a malicious FBX file which may exploit a buffer overflow vulnerability causin…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-7366
|
2024-11-21 13:48 |
2019-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212842
|
7.8 |
HIGH
Local
|
autodesk
|
autodesk_desktop
|
DLL preloading vulnerability in Autodesk Desktop Application versions 7.0.16.29 and earlier. An attacker may trick a user into downloading a malicious DLL file into the working directory, which may t…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-7365
|
2024-11-21 13:48 |
2019-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212843
|
8.3 |
HIGH
Network
|
cloudera
|
cdh
|
An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBackend, PamBackend, SpnegoDjangoBackend, RemoteUserDjangoBackend, SAML2Backend, …
|
CWE-269
Improper Privilege Management
|
CVE-2019-7319
|
2024-11-21 13:48 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212844
|
7.5 |
HIGH
Network
|
elastic
|
logstash
|
Logstash versions before 7.4.1 and 6.8.4 contain a denial of service flaw in the Logstash Beats input plugin. An unauthenticated user who is able to connect to the port the Logstash beats input could…
|
NVD-CWE-noinfo
|
CVE-2019-7620
|
2024-11-21 13:48 |
2019-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212845
|
5.3 |
MEDIUM
Network
|
elastic
|
elasticsearch
|
Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker could send a specially crafted request and determin…
|
NVD-CWE-noinfo
|
CVE-2019-7619
|
2024-11-21 13:48 |
2019-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212846
|
6.5 |
MEDIUM
Network
|
elastic
|
kibana
|
A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is possible to read arbitrary files from the local fil…
|
CWE-22
Path Traversal
|
CVE-2019-7618
|
2024-11-21 13:48 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212847
|
7.8 |
HIGH
Local
|
autodesk
|
design_review
|
Use-after-free vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a use-after-free vulnerabi…
|
CWE-416
Use After Free
|
CVE-2019-7363
|
2024-11-21 13:48 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212848
|
7.8 |
HIGH
Local
|
autodesk
|
design_review
|
DLL preloading vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a DLL preloading vulnerabi…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-7362
|
2024-11-21 13:48 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212849
|
7.8 |
HIGH
Local
|
autodesk
|
advance_steel autocad autocad_architecture autocad_electrical autocad_lt autocad_map_3d autocad_mechanical autocad_mep autocad_plant_3d civil_3d autocad_p\&id
|
DLL preloading vulnerability in versions 2017, 2018, 2019, and 2020 of Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechan…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-7364
|
2024-11-21 13:48 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212850
|
7.2 |
HIGH
Network
|
elastic
|
apm_agent
|
When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can control the proxy header. This could result in an atta…
|
CWE-20
Improper Input Validation
|
CVE-2019-7617
|
2024-11-21 13:48 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|