|
222511
|
4.7 |
MEDIUM
Local
|
microchip tecsec thalesgroup cryptsoft athena-scs
|
atmel_toolbox armored_card etoken_4300 s\/a_idflex_v idprotect
|
Smart cards from the Athena SCS manufacturer, based on the Atmel Toolbox 00.03.11.05 and the AT90SC chip, contain a timing side channel in ECDSA signature generation. This allows a local attacker, ab…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-15809
|
2024-11-21 13:29 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222512
|
9.8 |
CRITICAL
Network
|
govicture
|
pc530_firmware
|
Victure PC530 devices allow unauthenticated TELNET access as root.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-15940
|
2024-11-21 13:29 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222513
|
6.1 |
MEDIUM
Network
|
netdisco
|
netdisco
|
Insufficient sanitization during device search in Netdisco 2.042010 allows for reflected XSS via manipulation of a URL parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15810
|
2024-11-21 13:29 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222514
|
5.3 |
MEDIUM
Network
|
cksource
|
ckfinder
|
An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0. The documentation has misleading information that could lead to a conclusion that the application has a built-in bulletproof…
|
CWE-200
Information Exposure
|
CVE-2019-15891
|
2024-11-21 13:29 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222515
|
7.5 |
HIGH
Network
|
cksource
|
ckfinder
|
An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload files without any extension (even if the application was configured to accept file…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-15862
|
2024-11-21 13:29 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222516
|
9.8 |
CRITICAL
Network
|
lemonldap-ng debian
|
lemonldap\ debian_linux
|
OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request. To be vulnerable, there must exist an…
|
CWE-863
Incorrect Authorization
|
CVE-2019-15941
|
2024-11-21 13:29 |
2019-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222517
|
9.1 |
CRITICAL
Network
|
suricata-ids
|
suricata
|
An issue was discovered in app-layer-ssl.c in Suricata 4.1.4. Upon receiving a corrupted SSLv3 (TLS 1.2) packet, the parser function TLSDecodeHSHelloExtensions tries to access a memory region that is…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15699
|
2024-11-21 13:29 |
2019-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222518
|
4.9 |
MEDIUM
Network
|
grafana
|
grafana
|
An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and …
|
CWE-319 CWE-522
Cleartext Transmission of Sensitive Information Insufficiently Protected Credentials
|
CVE-2019-15635
|
2024-11-21 13:29 |
2019-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222519
|
8.8 |
HIGH
Network
|
valvesoftware
|
counter-strike\
|
vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this serve…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-15943
|
2024-11-21 13:29 |
2019-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222520
|
7.4 |
HIGH
Network
|
mi
|
xiaomi_millet_firmware
|
A malicious file upload vulnerability was discovered in Xiaomi Millet mobile phones 1-6.3.9.3. A particular condition involving a man-in-the-middle attack may lead to partial data leakage or maliciou…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-15843
|
2024-11-21 13:29 |
2019-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|