|
222141
|
7.2 |
HIGH
Network
|
dell
|
emc_data_protection_advisor emc_integrated_data_protection_appliance_firmware
|
Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server-side template injection vulnerability in the REST API. A…
|
CWE-94
Code Injection
|
CVE-2019-18582
|
2024-11-21 13:33 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222142
|
7.2 |
HIGH
Network
|
dell
|
emc_data_protection_advisor emc_integrated_data_protection_appliance_firmware
|
Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server missing authorization vulnerability in the REST API. A r…
|
CWE-862
Missing Authorization
|
CVE-2019-18581
|
2024-11-21 13:33 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222143
|
6.5 |
MEDIUM
Network
|
hp
|
envy_5000_m2u85a_firmware envy_5000_m2u85b_firmware envy_5000_m2u91a_firmware envy_5000_m2u94b_firmware envy_5000_z4a54a_firmware envy_5000_z4a74a_firmware deskjet_ink_advantage_500…
|
A potential security vulnerability has been identified for certain HP Printers and All-in-Ones that would allow bypassing account lockout.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2019-18917
|
2024-11-21 13:33 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222144
|
9.0 |
CRITICAL
Network
|
dell
|
xtremio_management_server
|
Dell EMC XtremIO XMS versions prior to 6.3.0 contain a stored cross-site scripting vulnerability. A low-privileged malicious remote user of XtremIO may exploit this vulnerability to store malicious H…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18578
|
2024-11-21 13:33 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222145
|
6.7 |
MEDIUM
Local
|
dell
|
xtremio_management_server
|
Dell EMC XtremIO XMS versions prior to 6.3.0 contain an incorrect permission assignment vulnerability. A malicious local user with XtremIO xinstall privileges may exploit this vulnerability to gain r…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-18577
|
2024-11-21 13:33 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222146
|
6.7 |
MEDIUM
Local
|
dell
|
xtremio_management_server
|
Dell EMC XtremIO XMS versions prior to 6.3.0 contain an information disclosure vulnerability where OS users’ passwords are logged in local files. Malicious local users with access to the log files ma…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-18576
|
2024-11-21 13:33 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222147
|
7.5 |
HIGH
Network
|
siemens
|
simatic_s7-300_cpu_firmware simatic_s7-300_cpu_312_ifm_firmware simatic_s7-300_cpu_313_firmware simatic_s7-300_cpu_314_firmware simatic_s7-300_cpu_314_ifm_firmware simatic_s7-300_cpu_3…
|
A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions < V3.X.17), SIMATIC TDC CP51M1 (All versions < V1.1.8), SIMATIC TDC CPU55…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-18336
|
2024-11-21 13:33 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222148
|
5.9 |
MEDIUM
Network
|
mitel
|
6863i_firmware 6865i_firmware 6867i_firmware 6869i_firmware 6873i_firmware 6920_firmware 6930_firmware 6940_firmware
|
A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versions 5.1.0.2051 SP2 and earlier, could allow an attacker to launch a man-in-the-…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2019-18863
|
2024-11-21 13:33 |
2020-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222149
|
9.8 |
CRITICAL
Network
|
suse opensuse
|
linux_enterprise_server leap
|
A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remote attackers to cause DoS or potentially code exec…
|
CWE-416
Use After Free
|
CVE-2019-18903
|
2024-11-21 13:33 |
2020-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222150
|
9.8 |
CRITICAL
Network
|
suse opensuse
|
linux_enterprise_server leap
|
A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remote attackers to cause DoS or potentially code exec…
|
CWE-416
Use After Free
|
CVE-2019-18902
|
2024-11-21 13:33 |
2020-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|