|
218761
|
4.9 |
MEDIUM
Network
|
huawei
|
usg9500_firmware
|
USG9500 with versions of V500R001C30;V500R001C60 have a missing integrity checking vulnerability. The software of the affected products does not check the integrity which may allow an attacker with h…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2019-5272
|
2024-11-21 13:44 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218762
|
6.5 |
MEDIUM
Adjacent
|
linux debian canonical netapp oracle
|
linux_kernel debian_linux ubuntu_linux cloud_backup steelstore_cloud_integrated_storage data_availability_services solidfire hci_management_node active_iq_unified_manager e…
|
An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location updates for statio…
|
CWE-287
Improper Authentication
|
CVE-2019-5108
|
2024-11-21 13:44 |
2019-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218763
|
8.8 |
HIGH
Adjacent
|
huawei
|
elle-al00b_firmware
|
Huawei smart phones with earlier versions than ELLE-AL00B 9.1.0.222(C00E220R2P1) have a buffer overflow vulnerability. An attacker may intercept and tamper with the packet in the local area network (…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-5276
|
2024-11-21 13:44 |
2019-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218764
|
5.5 |
MEDIUM
Local
|
huawei
|
oceanstor_sns3096_firmware
|
Huawei OceanStor SNS3096 V100R002C01 have an information disclosure vulnerability. Attackers with low privilege can exploit this vulnerability by performing some specific operations. Successful explo…
|
NVD-CWE-noinfo
|
CVE-2019-5267
|
2024-11-21 13:44 |
2019-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218765
|
7.5 |
HIGH
Network
|
huawei
|
p30_firmware
|
Huawei Share function in P30 9.1.0.193(C00E190R2P1) smartphone has an insufficient input validation vulnerability. Attackers can exploit this vulnerability by sending crafted packets to the affected …
|
CWE-20
Improper Input Validation
|
CVE-2019-5266
|
2024-11-21 13:44 |
2019-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218766
|
7.5 |
HIGH
Network
|
huawei
|
p30_firmware
|
Huawei Share function in P30 9.1.0.193(C00E190R2P1) smartphone has an improper access control vulnerability. The function incorrectly controls certain access messages, attackers can simulate a sender…
|
NVD-CWE-noinfo
|
CVE-2019-5265
|
2024-11-21 13:44 |
2019-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218767
|
6.1 |
MEDIUM
Network
|
ibm
|
financial_transaction_manager_for_multiplatform
|
IBM Financial Transaction Manager 3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality …
|
CWE-79
Cross-site Scripting
|
CVE-2019-4744
|
2024-11-21 13:44 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218768
|
4.3 |
MEDIUM
Network
|
ibm
|
financial_transaction_manager_for_multiplatform
|
IBM Financial Transaction Manager 3.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user …
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-4743
|
2024-11-21 13:44 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218769
|
6.1 |
MEDIUM
Network
|
ibm
|
financial_transaction_manager_for_multiplatform
|
IBM Financial Transaction Manager 3.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit …
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2019-4742
|
2024-11-21 13:44 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218770
|
4.3 |
MEDIUM
Network
|
ibm
|
financial_transaction_manager_for_multiplatform
|
IBM Financial Transaction Manager 3.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website …
|
CWE-352
Origin Validation Error
|
CVE-2019-4736
|
2024-11-21 13:44 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|