|
221911
|
9.8 |
CRITICAL
Network
|
broadcom
|
nolio
|
An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacker to execute arbitrary code.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-19230
|
2024-11-21 13:34 |
2019-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221912
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in f2fs_build_segment_manager in fs/f2fs/segment.c, related to init_min_max_mtime in fs…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-19449
|
2024-11-21 13:34 |
2019-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221913
|
7.8 |
HIGH
Local
|
linux debian canonical netapp
|
linux_kernel debian_linux ubuntu_linux cloud_backup steelstore_cloud_integrated_storage data_availability_services solidfire hci_management_node active_iq_unified_manager a…
|
In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space…
|
CWE-416
Use After Free
|
CVE-2019-19448
|
2024-11-21 13:34 |
2019-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221914
|
7.8 |
HIGH
Local
|
linux netapp
|
linux_kernel cloud_backup steelstore_cloud_integrated_storage data_availability_services active_iq_unified_manager solidfire_baseboard_management_controller hci_baseboard_management…
|
In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lead to a use-after-free in ext4_put_super in fs/ext4/super.c, related to dump_orp…
|
CWE-416
Use After Free
|
CVE-2019-19447
|
2024-11-21 13:34 |
2019-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221915
|
4.8 |
MEDIUM
Network
|
sangoma
|
freepbx
|
In userman 13.0.76.43 through 15.0.20 in Sangoma FreePBX, XSS exists in the user management screen of the Administrator web site, i.e., the/admin/config.php?display=userman URI. An attacker with suff…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19552
|
2024-11-21 13:34 |
2019-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221916
|
9.8 |
CRITICAL
Network
|
cesnet redhat fedoraproject
|
libyang enterprise_linux fedora
|
In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "identityref". An application that uses libyang to pars…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-19334
|
2024-11-21 13:34 |
2019-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221917
|
4.8 |
MEDIUM
Network
|
sangoma
|
freepbx
|
In userman 13.0.76.43 through 15.0.20 in Sangoma FreePBX, XSS exists in the User Management screen of the Administrator web site. An attacker with access to the User Control Panel application can sub…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19551
|
2024-11-21 13:34 |
2019-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221918
|
9.8 |
CRITICAL
Network
|
cesnet redhat
|
libyang enterprise_linux
|
In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "bits". An application that uses libyang to parse untru…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-19333
|
2024-11-21 13:34 |
2019-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221919
|
6.5 |
MEDIUM
Network
|
norton
|
password_manager
|
Norton Password Manager, prior to 6.6.2.5, may be susceptible to an information disclosure issue, which is a type of vulnerability whereby there is an unintentional disclosure of information to an ac…
|
NVD-CWE-noinfo
|
CVE-2019-19546
|
2024-11-21 13:34 |
2019-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221920
|
6.3 |
MEDIUM
Network
|
norton
|
password_manager
|
Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, which is a type of issue that allows restricted resources on a web page to be re…
|
CWE-346
Origin Validation Error
|
CVE-2019-19545
|
2024-11-21 13:34 |
2019-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|