|
222891
|
7.8 |
HIGH
Local
|
intel
|
nuc_8_mainstream_game_kit_firmware nuc_8_mainstream_game_mini_computer_firmware nuc8i7bek_firmware cd1p64gk_firmware nuc8i3cysm_firmware nuc8i7hnk_firmware nuc7i7dnke_firmware nu…
|
Improper access control in firmware for Intel(R) NUC(R) may allow an authenticated user to potentially enable escalation of privilege via local access.
|
NVD-CWE-Other
|
CVE-2019-14610
|
2024-11-21 13:27 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222892
|
6.7 |
MEDIUM
Local
|
intel
|
nuc_8_mainstream_game_kit_firmware nuc_8_mainstream_game_mini_computer_firmware nuc8i7bek_firmware cd1p64gk_firmware nuc8i3cysm_firmware nuc8i7hnk_firmware nuc7i7dnke_firmware nu…
|
Improper input validation in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation of privilege via local access.
|
CWE-20
Improper Input Validation
|
CVE-2019-14609
|
2024-11-21 13:27 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222893
|
7.8 |
HIGH
Local
|
intel
|
nuc_8_mainstream_game_kit_firmware nuc_8_mainstream_game_mini_computer_firmware nuc8i7bek_firmware cd1p64gk_firmware nuc8i3cysm_firmware nuc8i7hnk_firmware nuc7i7dnke_firmware nu…
|
Improper buffer restrictions in firmware for Intel(R) NUC(R) may allow an authenticated user to potentially enable escalation of privilege via local access.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-14608
|
2024-11-21 13:27 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222894
|
7.8 |
HIGH
Local
|
intel
|
setup_and_configuration_software_platform_discovery_utility
|
Improper permissions in the installer for the Intel(R) SCS Platform Discovery Utility, all versions, may allow an authenticated user to potentially enable escalation of privilege via local attack.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-14605
|
2024-11-21 13:27 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222895
|
5.5 |
MEDIUM
Local
|
intel
|
quartus_prime
|
Null pointer dereference in the FPGA kernel driver for Intel(R) Quartus(R) Prime Pro Edition before version 19.3 may allow an authenticated user to potentially enable denial of service via local acce…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-14604
|
2024-11-21 13:27 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222896
|
7.8 |
HIGH
Local
|
intel
|
quartus_prime
|
Improper permissions in the installer for the License Server software for Intel® Quartus® Prime Pro Edition before version 19.3 may allow an authenticated user to potentially enable escalation of pri…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-14603
|
2024-11-21 13:27 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222897
|
7.8 |
HIGH
Local
|
intel
|
control_center-i
|
Unquoted service path in Control Center-I version 2.1.0.0 and earlier may allow an authenticated user to potentially enable escalation of privilege via local access.
|
CWE-426
Untrusted Search Path
|
CVE-2019-14599
|
2024-11-21 13:27 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222898
|
5.4 |
MEDIUM
Network
|
redhat
|
3scale
|
A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to conduct cross site scripting attacks and gain acce…
|
-
|
CVE-2019-14849
|
2024-11-21 13:27 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222899
|
4.3 |
MEDIUM
Network
|
atlassian
|
crucible fisheye
|
The /json/profile/removeStarAjax.do resource in Atlassian Fisheye and Crucible before version 4.8.0 allows remote attackers to remove another user's favourite setting for a project via an improper au…
|
NVD-CWE-noinfo
|
CVE-2019-15009
|
2024-11-21 13:27 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222900
|
6.1 |
MEDIUM
Network
|
atlassian
|
crucible fisheye
|
The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulne…
|
CWE-79
Cross-site Scripting
|
CVE-2019-15008
|
2024-11-21 13:27 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|