|
218741
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new merge requests endpoint to disclose label names.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-5466
|
2024-11-21 13:44 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218742
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which could result in disclosure of the newly created issue ID.
|
NVD-CWE-noinfo
|
CVE-2019-5465
|
2024-11-21 13:44 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218743
|
9.8 |
CRITICAL
Network
|
gitlab
|
gitlab
|
A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the library is utilized.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-5464
|
2024-11-21 13:44 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218744
|
8.8 |
HIGH
Network
|
gitlab
|
gitlab
|
A privilege escalation issue was discovered in GitLab CE/EE 9.0 and later when trigger tokens are not rotated once ownership of them has changed.
|
CWE-613
Insufficient Session Expiration
|
CVE-2019-5462
|
2024-11-21 13:44 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218745
|
9.0 |
CRITICAL
Network
|
amd
|
atidxx64
|
An exploitable type confusion vulnerability exists in AMD ATIDXX64.DLL driver, versions 26.20.13031.10003, 26.20.13031.15006 and 26.20.13031.18002. A specially crafted pixel shader can cause a type c…
|
CWE-843
Type Confusion
|
CVE-2019-5183
|
2024-11-21 13:44 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218746
|
8.6 |
HIGH
Network
|
amd
|
atidxx64
|
An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13003.1007. A specially crafted pixel shader can cause a denial of service. An attacker can provide a …
|
CWE-125
Out-of-bounds Read
|
CVE-2019-5147
|
2024-11-21 13:44 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218747
|
8.6 |
HIGH
Network
|
amd
|
atidxx64
|
An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13025.10004. A specially crafted pixel shader can cause a denial of service. An attacker can provide a…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-5146
|
2024-11-21 13:44 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218748
|
8.6 |
HIGH
Network
|
amd
|
atidxx64
|
An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.50005. A specially crafted pixel shader can cause a denial of service. An attacker can provide a…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-5124
|
2024-11-21 13:44 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218749
|
8.8 |
HIGH
Network
|
foxitsoftware
|
phantompdf reader
|
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit PDF Reader, version 9.7.0.29435. A specially crafted PDF document can trigger a previously freed object in memory …
|
CWE-416
Use After Free
|
CVE-2019-5145
|
2024-11-21 13:44 |
2020-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218750
|
8.8 |
HIGH
Network
|
foxitsoftware
|
phantompdf reader
|
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit PDF Reader, version 9.7.0.29435. A specially crafted PDF document can trigger a previously freed object in memory …
|
CWE-416
Use After Free
|
CVE-2019-5126
|
2024-11-21 13:44 |
2020-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|