|
222821
|
5.5 |
MEDIUM
Local
|
suse opensuse
|
linux_enterprise_server leap
|
A UNIX Symbolic Link (Symlink) Following vulnerability in the mysql-systemd-helper of the mariadb packaging of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allows local attackers …
|
-
|
CVE-2019-18901
|
2024-11-21 13:33 |
2020-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222822
|
7.8 |
HIGH
Local
|
suse opensuse
|
linux_enterprise_server leap
|
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Factory allows local attackers to escalat…
|
-
|
CVE-2019-18897
|
2024-11-21 13:33 |
2020-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222823
|
5.0 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite through 7.10.2 allows SSRF.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-18846
|
2024-11-21 13:33 |
2020-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222824
|
8.2 |
HIGH
Adjacent
|
phoenixcontact
|
fl_nat_2208_firmware fl_nat_2304-2gc-2sfp_firmware
|
Improper access control exists on PHOENIX CONTACT FL NAT 2208 devices before V2.90 and FL NAT 2304-2GC-2SFP devices before V2.90 when using MAC-based port security.
|
NVD-CWE-noinfo
|
CVE-2019-18352
|
2024-11-21 13:33 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222825
|
7.1 |
HIGH
Network
|
hitachienergy
|
asset_suite
|
Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables full access to directly referenced objects. An at…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-18998
|
2024-11-21 13:33 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222826
|
5.4 |
MEDIUM
Network
|
lexmark
|
cx31x_firmware cx41x_firmware cx310_firmware ms310_firmware ms312_firmware ms317_firmware ms410_firmware m1140_firmware ms315_firmware ms415_firmware ms417_firmware m…
|
Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and ot…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18791
|
2024-11-21 13:33 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222827
|
7.8 |
HIGH
Local
|
hp
|
system_event_utility
|
A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version 1.4.33. This vulnerability may allow a local attacker to execute arbitrary cod…
|
CWE-428
Unquoted Search Path or Element
|
CVE-2019-18915
|
2024-11-21 13:33 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222828
|
7.0 |
HIGH
Local
|
teamviewer
|
teamviewer
|
TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' installations. It used a shared AES key for all installations…
|
CWE-521
Weak Password Requirements
|
CVE-2019-18988
|
2024-11-21 13:33 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222829
|
6.3 |
MEDIUM
Local
|
hp
|
bromium
|
Bromium client version 4.0.3.2060 and prior to 4.1.7 Update 1 has an out of bound read results in race condition causing Kernel memory leaks or denial of service.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-18567
|
2024-11-21 13:33 |
2020-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222830
|
6.8 |
MEDIUM
Physics
|
hp
|
elitedesk_800_g5_dm_firmware elitedesk_800_g5_sff_firmware elitedesk_800_g5_twr_firmware eliteone_800_g5_aio_firmware prodesk_400_g5_dm_firmware prodesk_400_g6_mt_firmware prodesk_4…
|
A potential security vulnerability with pre-boot DMA may allow unauthorized UEFI code execution using open-case attacks. This industry-wide issue requires physically accessing internal expansion slot…
|
NVD-CWE-noinfo
|
CVE-2019-18913
|
2024-11-21 13:33 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|