|
221841
|
6.1 |
MEDIUM
Network
|
symantec fedoraproject
|
endpoint_detection_and_response fedora
|
Symantec Endpoint Detection and Response (SEDR), prior to 4.3.0, may be susceptible to a cross site scripting (XSS) issue. XSS is a type of issue that can enable attackers to inject client-side scrip…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19547
|
2024-11-21 13:34 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221842
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_applications_manager
|
An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is prone to attack due to lack of file permission sec…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-19475
|
2024-11-21 13:34 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221843
|
6.1 |
MEDIUM
Local
|
linux redhat
|
linux_kernel enterprise_linux
|
An out-of-bounds memory write issue was found in the Linux Kernel, version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get …
|
-
|
CVE-2019-19332
|
2024-11-21 13:34 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221844
|
8.8 |
HIGH
Network
|
sagemcom netgear technicolor compal
|
f\@st_3890_firmware f\@st_3686_firmware cg3700emr_firmware c6250emr_firmware tc7230_steb_firmware 7284e_firmware 7486e_firmware
|
Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrary code at the kernel level via JavaScript run in a victim's …
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-19494
|
2024-11-21 13:34 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221845
|
9.8 |
CRITICAL
Network
|
technicolor
|
tc7230_steb_firmware
|
The web interface on the Technicolor TC7230 STEB 01.25 is vulnerable to DNS rebinding, which allows a remote attacker to configure the cable modem via JavaScript in a victim's browser. The attacker c…
|
CWE-20
Improper Input Validation
|
CVE-2019-19495
|
2024-11-21 13:34 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221846
|
7.8 |
HIGH
Local
|
broadcom
|
ca_automic_dollar_universe
|
CA Automic Dollar Universe 5.3.3 contains a vulnerability, related to the uxdqmsrv binary being setuid root, that allows local attackers to elevate privileges. This vulnerability was reported to CA s…
|
CWE-269
Improper Privilege Management
|
CVE-2019-19544
|
2024-11-21 13:34 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221847
|
9.8 |
CRITICAL
Network
|
broadcom
|
ca_automic_sysload
|
CA Automic Sysload 5.6.0 through 6.1.2 contains a vulnerability, related to a lack of authentication on the File Server port, that potentially allows remote attackers to execute arbitrary commands.
|
CWE-287
Improper Authentication
|
CVE-2019-19518
|
2024-11-21 13:34 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221848
|
7.8 |
HIGH
Local
|
rconfig
|
rconfig
|
An issue was discovered in rConfig 3.9.3. The install script updates the /etc/sudoers file for rconfig specific tasks. After an "rConfig specific Apache configuration" update, apache has high privile…
|
CWE-269
Improper Privilege Management
|
CVE-2019-19585
|
2024-11-21 13:34 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221849
|
8.8 |
HIGH
Network
|
rconfig
|
rconfig
|
An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a GET request to ajaxArchiveFiles.php because the path parameter is passed to the…
|
CWE-78
OS Command
|
CVE-2019-19509
|
2024-11-21 13:34 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221850
|
6.1 |
MEDIUM
Network
|
icewarp
|
mail_server
|
IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 1 of 2) in notes for contacts.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19265
|
2024-11-21 13:34 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|