|
222291
|
2.7 |
LOW
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 2 of 4).
|
CWE-281
Improper Preservation of Permissions
|
CVE-2019-18458
|
2024-11-21 13:33 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222292
|
8.8 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition 11.8 through 12.4 when handling Security tokens.. It has Insecure Permissions.
|
CWE-281
Improper Preservation of Permissions
|
CVE-2019-18457
|
2024-11-21 13:33 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222293
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 4 of 4).
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-18463
|
2024-11-21 13:33 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222294
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4. It has Insecure Permissions.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-18462
|
2024-11-21 13:33 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222295
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.3 when a sub group epic is added to a public group. It has Incorrect Access Control.
|
CWE-200
Information Exposure
|
CVE-2019-18461
|
2024-11-21 13:33 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222296
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature provided by the Elasticsearch integration. It has Incorrect Access Control.
|
CWE-200
Information Exposure
|
CVE-2019-18460
|
2024-11-21 13:33 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222297
|
9.8 |
CRITICAL
Network
|
broadcom
|
symantec_critical_system_protection
|
Symantec Critical System Protection (CSP), versions 8.0, 8.0 HF1 & 8.0 MP1, may be susceptible to an authentication bypass vulnerability, which is a type of issue that can potentially allow a threat …
|
CWE-287
Improper Authentication
|
CVE-2019-18374
|
2024-11-21 13:33 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222298
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
The Linux kernel through 5.3.13 has a start_offset+size Integer Overflow in cpia2_remap_buffer in drivers/media/usb/cpia2/cpia2_core.c because cpia2 has its own mmap implementation. This allows local…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-18675
|
2024-11-21 13:33 |
2019-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222299
|
6.8 |
MEDIUM
Physics
|
hp
|
thinpro
|
The Citrix Receiver wrapper function does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with local user privileges.
|
CWE-78
OS Command
|
CVE-2019-18910
|
2024-11-21 13:33 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222300
|
8.0 |
HIGH
Adjacent
|
hp
|
thinpro
|
The VPN software within HP ThinPro does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with root privileges.
|
CWE-78
OS Command
|
CVE-2019-18909
|
2024-11-21 13:33 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|