|
221991
|
6.1 |
MEDIUM
Network
|
fusionpbx
|
fusionpbx
|
A cross-site scripting (XSS) vulnerability in app/fifo_list/fifo_interactive.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the c parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19387
|
2024-11-21 13:34 |
2019-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221992
|
6.1 |
MEDIUM
Network
|
fusionpbx
|
fusionpbx
|
A cross-site scripting (XSS) vulnerability in app/voicemail_greetings/voicemail_greeting_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the id and/or v…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19386
|
2024-11-21 13:34 |
2019-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221993
|
6.1 |
MEDIUM
Network
|
fusionpbx
|
fusionpbx
|
A cross-site scripting (XSS) vulnerability in app/dialplans/dialplans.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the app_uuid parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19385
|
2024-11-21 13:34 |
2019-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221994
|
6.1 |
MEDIUM
Network
|
fusionpbx
|
fusionpbx
|
A cross-site scripting (XSS) vulnerability in app/fax/fax_log_view.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the fax_uuid parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19384
|
2024-11-21 13:34 |
2019-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221995
|
5.3 |
MEDIUM
Network
|
misp
|
misp
|
In app/Controller/TagsController.php in MISP 2.4.118, users can bypass intended restrictions on tagging data.
|
NVD-CWE-noinfo
|
CVE-2019-19379
|
2024-11-21 13:34 |
2019-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221996
|
6.5 |
MEDIUM
Network
|
octopus
|
octopus_deploy
|
In Octopus Deploy before 2019.10.6, an authenticated user with TeamEdit permission could send a malformed Team API request that bypasses input validation and causes an application level denial of ser…
|
CWE-20 CWE-476
Improper Input Validation NULL Pointer Dereference
|
CVE-2019-19376
|
2024-11-21 13:34 |
2019-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221997
|
5.3 |
MEDIUM
Network
|
octopus
|
octopus_deploy
|
In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes sent without the secure attribute. (The fix for this was backported to LTS versio…
|
CWE-352
Origin Validation Error
|
CVE-2019-19375
|
2024-11-21 13:34 |
2019-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221998
|
7.5 |
HIGH
Network
|
rconfig
|
rconfig
|
A downloadFile.php download_file path traversal vulnerability in rConfig through 3.9.3 allows attackers to list files in arbitrary folders and potentially download files. NOTE: the discoverer later r…
|
CWE-22
Path Traversal
|
CVE-2019-19372
|
2024-11-21 13:34 |
2019-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221999
|
6.5 |
MEDIUM
Local
|
linux redhat opensuse
|
linux_kernel enterprise_linux leap
|
In the Linux kernel before 5.2, a setxattr operation, after a mount of a crafted ext4 image, can cause a slab-out-of-bounds write access because of an ext4_xattr_set_entry use-after-free in fs/ext4/x…
|
CWE-787 CWE-416
Out-of-bounds Write Use After Free
|
CVE-2019-19319
|
2024-11-21 13:34 |
2019-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222000
|
4.4 |
MEDIUM
Local
|
linux opensuse canonical debian netapp
|
linux_kernel leap ubuntu_linux debian_linux steelstore_cloud_integrated_storage active_iq_unified_manager data_availability_services solidfire hci_management_node aff_a700s…
|
In the Linux kernel 5.3.11, mounting a crafted btrfs image twice can cause an rwsem_down_write_slowpath use-after-free because (in rwsem_can_spin_on_owner in kernel/locking/rwsem.c) rwsem_owner_flags…
|
CWE-416
Use After Free
|
CVE-2019-19318
|
2024-11-21 13:34 |
2019-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|