|
222431
|
5.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-18367
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222432
|
5.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-18366
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222433
|
4.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages.
|
NVD-CWE-noinfo CWE-269
Improper Privilege Management
|
CVE-2019-18365
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222434
|
9.8 |
CRITICAL
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-18364
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222435
|
5.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2019.1.2, access could be gained to the history of builds of a deleted build configuration under some circumstances.
|
NVD-CWE-noinfo
|
CVE-2019-18363
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222436
|
5.3 |
MEDIUM
Network
|
jetbrains
|
mps
|
JetBrains MPS before 2019.2.2 exposed listening ports to the network.
|
NVD-CWE-noinfo
|
CVE-2019-18362
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222437
|
5.3 |
MEDIUM
Local
|
jetbrains
|
intellij_idea
|
JetBrains IntelliJ IDEA before 2019.2 allows local user privilege escalation, potentially leading to arbitrary code execution.
|
NVD-CWE-noinfo
|
CVE-2019-18361
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222438
|
5.3 |
MEDIUM
Network
|
jetbrains
|
hub
|
In JetBrains Hub versions earlier than 2019.1.11738, username enumeration was possible through password recovery.
|
NVD-CWE-noinfo
|
CVE-2019-18360
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222439
|
9.8 |
CRITICAL
Network
|
xen debian fedoraproject opensuse
|
xen debian_linux fedora leap
|
An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. There is missing descriptor table limit checking in x8…
|
CWE-269
Improper Privilege Management
|
CVE-2019-18425
|
2024-11-21 13:33 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222440
|
6.8 |
MEDIUM
Physics
|
xen debian fedoraproject opensuse
|
xen debian_linux fedora leap
|
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device. This occurs because passe…
|
CWE-78
OS Command
|
CVE-2019-18424
|
2024-11-21 13:33 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|