|
218641
|
10.0 |
CRITICAL
Network
|
apple
|
iphone_os mac_os_x tv_os watch_os itunes
|
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3, iTunes 12.9.3 for Windows. A sandboxed process m…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-6235
|
2024-11-21 13:46 |
2019-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218642
|
9.8 |
CRITICAL
Network
|
apple
|
iphone_os
|
An issue existed with autofill resuming after it was canceled. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.3. Password autofill may fill in passwords after…
|
CWE-200
Information Exposure
|
CVE-2019-6206
|
2024-11-21 13:46 |
2019-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218643
|
7.5 |
HIGH
Network
|
pangea-comm
|
fax_ata
|
Pangea Communications Internet FAX ATA all Versions 3.1.8 and prior allow an attacker to bypass user authentication using a specially crafted URL to cause the device to reboot, which may be used to c…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2019-6551
|
2024-11-21 13:46 |
2019-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218644
|
5.5 |
MEDIUM
Local
|
deltaww
|
screeneditor
|
Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.84 and prior. An out-of-bounds read vulnerability may cause the software to crash due to lacking user input validation for proce…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-6547
|
2024-11-21 13:46 |
2019-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218645
|
7.8 |
HIGH
Local
|
hornerautomation
|
cscape
|
Cscape, 9.80 SP4 and prior. An improper input validation vulnerability may be exploited by processing specially crafted POC files. This may allow an attacker to read confidential information and remo…
|
CWE-20
Improper Input Validation
|
CVE-2019-6555
|
2024-11-21 13:46 |
2019-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218646
|
6.1 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager
|
Cross-site scripting (XSS) vulnerability in F5 BIG-IP Access Policy Manager (APM) 11.5.x and 11.6.x Admin Web UI.
|
CWE-79
Cross-site Scripting
|
CVE-2019-6595
|
2024-11-21 13:46 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218647
|
5.9 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager big-ip_local_traffic_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_security_manager big-ip_domain_name_system big-ip_edge…
|
On BIG-IP 11.5.1-11.6.3.2, 12.1.3.4-12.1.3.7, 13.0.0 HF1-13.1.1.1, and 14.0.0-14.0.0.2, Multi-Path TCP (MPTCP) does not protect against multiple zero length DATA_FINs in the reassembly queue, which c…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-6594
|
2024-11-21 13:46 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218648
|
5.9 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager big-ip_local_traffic_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_security_manager big-ip_domain_name_system big-ip_edge…
|
On BIG-IP 11.5.1-11.5.4, 11.6.1, and 12.1.0, a virtual server configured with a Client SSL profile may be vulnerable to a chosen ciphertext attack against CBC ciphers. When exploited, this may result…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-6593
|
2024-11-21 13:46 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218649
|
9.1 |
CRITICAL
Network
|
f5
|
big-ip_access_policy_manager big-ip_local_traffic_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_security_manager big-ip_domain_name_system big-ip_edge…
|
On BIG-IP 14.1.0-14.1.0.1, TMM may restart and produce a core file when validating SSL certificates in client SSL or server SSL profiles.
|
CWE-295
Improper Certificate Validation
|
CVE-2019-6592
|
2024-11-21 13:46 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218650
|
9.8 |
CRITICAL
Network
|
cordaware
|
bestinformed
|
Cordaware bestinformed Microsoft Windows client before 6.2.1.0 is affected by insecure SSL certificate verification and insecure access patterns. These issues allow remote attackers to downgrade encr…
|
CWE-295
Improper Certificate Validation
|
CVE-2019-6266
|
2024-11-21 13:46 |
2019-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|