|
223431
|
6.1 |
MEDIUM
Network
|
alcatelmobile
|
cingular_flip_2_firmware
|
On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an undocumented web API that allows unprivileged JavaScript, including JavaScript running within the KaiOS browser, to view and edit the devic…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-16243
|
2024-11-21 13:30 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223432
|
6.8 |
MEDIUM
Physics
|
alcatelmobile
|
cingular_flip_2_firmware
|
On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an engineering application named omamock that is vulnerable to OS command injection. An attacker with physical access to the device can abuse …
|
CWE-78
OS Command
|
CVE-2019-16242
|
2024-11-21 13:30 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223433
|
6.8 |
MEDIUM
Physics
|
alcatelmobile
|
cingular_flip_2_firmware
|
On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, PIN authentication can be bypassed by creating a special file within the /data/local/tmp/ directory. The System application that implements the lock sc…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2019-16241
|
2024-11-21 13:30 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223434
|
6.8 |
MEDIUM
Physics
|
hp
|
thinpro
|
In HP ThinPro Linux 6.2, 6.2.1, 7.0 and 7.1, an attacker may be able to leverage the application filter bypass vulnerability to gain privileged access to create a file on the local file system whose …
|
NVD-CWE-noinfo
|
CVE-2019-16287
|
2024-11-21 13:30 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223435
|
6.8 |
MEDIUM
Physics
|
hp
|
thinpro_linux
|
An attacker may be able to bypass the OS application filter meant to restrict applications that can be executed by changing browser preferences to launch a separate process that in turn can execute a…
|
CWE-287
Improper Authentication
|
CVE-2019-16286
|
2024-11-21 13:30 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223436
|
4.6 |
MEDIUM
Physics
|
hp
|
thinpro_linux
|
If a local user has been configured and logged in, an unauthenticated attacker with physical access may be able to extract sensitive information onto a local drive.
|
CWE-200
Information Exposure
|
CVE-2019-16285
|
2024-11-21 13:30 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223437
|
7.8 |
HIGH
Local
|
centreon
|
centreon_web
|
Centreon Web 19.04.4 has weak permissions within the OVA (aka VMware virtual machine) and OVF (aka VirtualBox virtual machine) files, allowing attackers to gain privileges via a Trojan horse Centreon…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-16406
|
2024-11-21 13:30 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223438
|
7.2 |
HIGH
Network
|
centreon
|
centreon_web
|
Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code Execution by an administrator who can modify Macro Expression location setting…
|
NVD-CWE-noinfo
|
CVE-2019-16405
|
2024-11-21 13:30 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223439
|
8.8 |
HIGH
Network
|
jenkins
|
google_compute_engine
|
A cross-site request forgery vulnerability in Jenkins Google Compute Engine Plugin 4.1.1 and earlier in ComputeEngineCloud#doProvision could be used to provision new agents.
|
CWE-352
Origin Validation Error
|
CVE-2019-16548
|
2024-11-21 13:30 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223440
|
4.3 |
MEDIUM
Network
|
jenkins
|
google_compute_engine
|
Missing permission checks in various API endpoints in Jenkins Google Compute Engine Plugin 4.1.1 and earlier allow attackers with Overall/Read permission to obtain limited information about the plugi…
|
CWE-862
Missing Authorization
|
CVE-2019-16547
|
2024-11-21 13:30 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|