|
223211
|
7.8 |
HIGH
Local
|
londontrustmedia
|
private_internet_access_vpn_client
|
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The macOS…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-12577
|
2024-11-21 13:23 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223212
|
7.8 |
HIGH
Local
|
londontrustmedia
|
private_internet_access_vpn_client
|
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The openv…
|
CWE-426
Untrusted Search Path
|
CVE-2019-12576
|
2024-11-21 13:23 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223213
|
7.8 |
HIGH
Local
|
londontrustmedia
|
private_internet_access_vpn_client
|
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The root_…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-12575
|
2024-11-21 13:23 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223214
|
7.8 |
HIGH
Local
|
londontrustmedia
|
private_internet_access_vpn_client
|
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v1.0 for Windows could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The PI…
|
CWE-426
Untrusted Search Path
|
CVE-2019-12574
|
2024-11-21 13:23 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223215
|
7.1 |
HIGH
Local
|
londontrustmedia
|
private_internet_access_vpn_client
|
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attacker to overwrite arbitrary files. The openvpn_launc…
|
CWE-59
Link Following
|
CVE-2019-12573
|
2024-11-21 13:23 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223216
|
7.1 |
HIGH
Local
|
londontrustmedia
|
private_internet_access_vpn_client
|
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v0.9.8 beta (build 02099) for macOS could allow an authenticated, local attacker to overwrite arbitrary files. When …
|
CWE-59
Link Following
|
CVE-2019-12571
|
2024-11-21 13:23 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223217
|
5.9 |
MEDIUM
Network
|
squid-cache debian fedoraproject opensuse canonical
|
squid debian_linux fedora leap ubuntu_linux
|
An issue was discovered in Squid 2.x through 2.7.STABLE9, 3.x through 3.5.28, and 4.x through 4.7. When Squid is configured to use Basic Authentication, the Proxy-Authorization header is parsed via u…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-12529
|
2024-11-21 13:23 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223218
|
8.8 |
HIGH
Network
|
squid-cache fedoraproject debian canonical redhat
|
squid fedora debian_linux ubuntu_linux enterprise_linux enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus
|
An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid uses a global buffer to store the decoded data. Squid does not check that the d…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-12527
|
2024-11-21 13:23 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223219
|
9.8 |
CRITICAL
Network
|
squid-cache debian opensuse fedoraproject canonical
|
squid debian_linux leap fedora ubuntu_linux
|
An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7. When Squid is configured to use Digest authentication, it parses the header Proxy-Authorization. It searches for certain tok…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-12525
|
2024-11-21 13:23 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223220
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_assetexplorer
|
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via ResourcesAttachments.jsp with the parameter pageName.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12597
|
2024-11-21 13:23 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|