|
222971
|
9.8 |
CRITICAL
Network
|
technicolor
|
tc7230_steb_firmware
|
The web interface on the Technicolor TC7230 STEB 01.25 is vulnerable to DNS rebinding, which allows a remote attacker to configure the cable modem via JavaScript in a victim's browser. The attacker c…
|
CWE-20
Improper Input Validation
|
CVE-2019-19495
|
2024-11-21 13:34 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222972
|
7.8 |
HIGH
Local
|
broadcom
|
ca_automic_dollar_universe
|
CA Automic Dollar Universe 5.3.3 contains a vulnerability, related to the uxdqmsrv binary being setuid root, that allows local attackers to elevate privileges. This vulnerability was reported to CA s…
|
CWE-269
Improper Privilege Management
|
CVE-2019-19544
|
2024-11-21 13:34 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222973
|
9.8 |
CRITICAL
Network
|
broadcom
|
ca_automic_sysload
|
CA Automic Sysload 5.6.0 through 6.1.2 contains a vulnerability, related to a lack of authentication on the File Server port, that potentially allows remote attackers to execute arbitrary commands.
|
CWE-287
Improper Authentication
|
CVE-2019-19518
|
2024-11-21 13:34 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222974
|
7.8 |
HIGH
Local
|
rconfig
|
rconfig
|
An issue was discovered in rConfig 3.9.3. The install script updates the /etc/sudoers file for rconfig specific tasks. After an "rConfig specific Apache configuration" update, apache has high privile…
|
CWE-269
Improper Privilege Management
|
CVE-2019-19585
|
2024-11-21 13:34 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222975
|
8.8 |
HIGH
Network
|
rconfig
|
rconfig
|
An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a GET request to ajaxArchiveFiles.php because the path parameter is passed to the…
|
CWE-78
OS Command
|
CVE-2019-19509
|
2024-11-21 13:34 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222976
|
6.1 |
MEDIUM
Network
|
icewarp
|
mail_server
|
IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 1 of 2) in notes for contacts.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19265
|
2024-11-21 13:34 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222977
|
5.4 |
MEDIUM
Network
|
icewarp
|
mail_server
|
IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 2 of 2) in notes for objects.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19266
|
2024-11-21 13:34 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222978
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2019-19314
|
2024-11-21 13:34 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222979
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible to create, edit, or view issues and commits.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2019-19313
|
2024-11-21 13:34 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222980
|
5.8 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private p…
|
NVD-CWE-noinfo
|
CVE-2019-19312
|
2024-11-21 13:34 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|