|
222161
|
7.8 |
HIGH
Local
|
sudo_project debian
|
sudo debian_linux
|
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and ele…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-18634
|
2024-11-21 13:33 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222162
|
3.3 |
LOW
Local
|
opensuse
|
libzypp
|
: Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allowed local attackers to read a cookie store use…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-18900
|
2024-11-21 13:33 |
2020-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222163
|
5.5 |
MEDIUM
Local
|
apt-cacher-ng_project opensuse
|
apt-cacher-ng backports
|
The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt-cacher-ng with root privileges. This can allow local attackers to influence the outcome of these opera…
|
-
|
CVE-2019-18899
|
2024-11-21 13:33 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222164
|
7.8 |
HIGH
Local
|
suse opensuse
|
trousers leap
|
UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root…
|
-
|
CVE-2019-18898
|
2024-11-21 13:33 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222165
|
8.2 |
HIGH
Network
|
-
|
-
|
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulner…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18426
|
2024-11-21 13:33 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222166
|
7.0 |
HIGH
Local
|
squid_analysis_report_generator_project opensuse
|
squid_analysis_report_generator leap backports_sle
|
log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By default, it uses a fixed temporary directory /tmp/sarg. As the root user, sarg creates this direct…
|
CWE-362 CWE-59
Race Condition Link Following
|
CVE-2019-18932
|
2024-11-21 13:33 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222167
|
7.5 |
HIGH
Network
|
jetbrains
|
idetalk
|
JetBrains IDETalk plugin before version 193.4099.10 allows XXE
|
CWE-611
XXE
|
CVE-2019-18412
|
2024-11-21 13:33 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222168
|
7.8 |
HIGH
Local
|
avast
|
premium_security
|
In Avast Premium Security 19.8.2393, attackers can send a specially crafted request to the local web server run by Avast Antivirus on port 27275 to support Bank Mode functionality. A flaw in the proc…
|
CWE-78
OS Command
|
CVE-2019-18894
|
2024-11-21 13:33 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222169
|
5.4 |
MEDIUM
Network
|
dell
|
emc_unisphere_for_powermax emc_powermax
|
Dell EMC Unisphere for PowerMax versions prior to 9.1.0.9, Dell EMC Unisphere for PowerMax versions prior to 9.0.2.16, and Dell EMC PowerMax OS 5978.221.221 and 5978.479.479 contain a Cross-Site Scri…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18588
|
2024-11-21 13:33 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222170
|
6.1 |
MEDIUM
Network
|
video_downloader_project avg avast
|
video_downloader secure_browser
|
XSS in the Video Downloader component before 1.5 of Avast Secure Browser 77.1.1831.91 and AVG Secure Browser 77.0.1790.77 allows websites to execute their code in the context of this component. While…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18893
|
2024-11-21 13:33 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|