|
223591
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possible from some fatal error messages.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14884
|
2024-11-21 13:27 |
2020-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223592
|
5.3 |
MEDIUM
Network
|
moodle
|
moodle
|
A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were not disabled when a user's account was no longer ac…
|
CWE-862
Missing Authorization
|
CVE-2019-14883
|
2024-11-21 13:27 |
2020-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223593
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed in the Lesson edit page.
|
CWE-601
Open Redirect
|
CVE-2019-14882
|
2024-11-21 13:27 |
2020-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223594
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user email is displayed.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14881
|
2024-11-21 13:27 |
2020-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223595
|
9.1 |
CRITICAL
Network
|
redhat
|
jboss_enterprise_application_platform single_sign-on jboss_fuse jboss_data_grid wildfly openshift_application_runtimes
|
A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traffic sent from Wildf…
|
NVD-CWE-Other
|
CVE-2019-14887
|
2024-11-21 13:27 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223596
|
6.7 |
MEDIUM
Local
|
intel
|
field_programmable_gate_array_programmable_acceleration_card_n3000_firmware
|
Improper access control in PCIe function for the Intel® FPGA Programmable Acceleration Card N3000, all versions, may allow a privileged user to potentially enable escalation of privilege via local ac…
|
NVD-CWE-noinfo
|
CVE-2019-14626
|
2024-11-21 13:27 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223597
|
4.4 |
MEDIUM
Local
|
intel
|
field_programmable_gate_array_programmable_acceleration_card_n3000_firmware
|
Improper access control in on-card storage for the Intel® FPGA Programmable Acceleration Card N3000, all versions, may allow a privileged user to potentially enable denial of service via local access.
|
NVD-CWE-Other
|
CVE-2019-14625
|
2024-11-21 13:27 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223598
|
5.8 |
MEDIUM
Local
|
qemu
|
qemu
|
hw/display/bochs-display.c in QEMU 4.0.0 does not ensure a sufficient PCI config space allocation, leading to a buffer overflow involving the PCIe extended config space.
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-15034
|
2024-11-21 13:27 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223599
|
6.5 |
MEDIUM
Network
|
redhat
|
decision_manager process_automation_manager
|
A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_security_context. The encoding used for storing the passwords is B…
|
-
|
CVE-2019-14886
|
2024-11-21 13:27 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223600
|
9.8 |
CRITICAL
Network
|
fasterxml netapp oracle
|
jackson-databind steelstore_cloud_integrated_storage oncommand_api_services goldengate_stream_analytics
|
A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when u…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-14893
|
2024-11-21 13:27 |
2020-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|