|
218721
|
6.8 |
MEDIUM
Physics
|
vmware
|
fusion workstation esxi
|
VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.x before 14.1.7), Fusion (11.x before 11.0.3, 10.x before 1…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2019-5519
|
2024-11-21 13:45 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218722
|
8.8 |
HIGH
Network
|
vmware
|
fusion
|
VMware VMware Fusion (11.x before 11.0.3) contains a security vulnerability due to certain unauthenticated APIs accessible through a web socket. An attacker may exploit this issue by tricking the hos…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-5514
|
2024-11-21 13:45 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218723
|
6.8 |
MEDIUM
Physics
|
vmware
|
fusion workstation esxi
|
VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.x before 14.1.7), Fusion (11.x before 11.0.3, 10.x before 1…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2019-5518
|
2024-11-21 13:45 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218724
|
9.8 |
CRITICAL
Network
|
vmware
|
vcloud_director
|
VMware vCloud Director for Service Providers 9.5.x prior to 9.5.0.3 update resolves a Remote Session Hijack vulnerability in the Tenant and Provider Portals. Successful exploitation of this issue may…
|
CWE-384
Session Fixation
|
CVE-2019-5523
|
2024-11-21 13:45 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218725
|
9.8 |
CRITICAL
Network
|
overit
|
geocall
|
An issue was discovered in OverIT Geocall 6.3 before build 2:346977. An unauthenticated servlet allows an attacker to obtain a cookie of an authenticated user, and login to the web application.
|
NVD-CWE-noinfo
|
CVE-2019-5891
|
2024-11-21 13:45 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218726
|
8.8 |
HIGH
Network
|
overit
|
geocall
|
An issue was discovered in OverIT Geocall 6.3 before build 2:346977. Weak authentication and session management allows an authenticated user to obtain access to the Administrative control panel and e…
|
CWE-287
Improper Authentication
|
CVE-2019-5890
|
2024-11-21 13:45 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218727
|
7.5 |
HIGH
Network
|
overit
|
geocall
|
An log-management directory traversal issue was discovered in OverIT Geocall 6.3 before build 2:346977.
|
CWE-22
Path Traversal
|
CVE-2019-5889
|
2024-11-21 13:45 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218728
|
6.1 |
MEDIUM
Network
|
overit
|
geocall
|
Multiple XSS vulnerabilities were discovered in OverIT Geocall 6.3 before build 2:346977.
|
CWE-79
Cross-site Scripting
|
CVE-2019-5888
|
2024-11-21 13:45 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218729
|
7.5 |
HIGH
Network
|
nodejs opensuse
|
node.js leap
|
Keep-alive HTTP and HTTPS connections can remain open and inactive for up to 2 minutes in Node.js 6.16.0 and earlier. Node.js 8.0.0 introduced a dedicated server.keepAliveTimeout which defaults to 5 …
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-5739
|
2024-11-21 13:45 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218730
|
7.5 |
HIGH
Network
|
nodejs opensuse
|
node.js leap
|
In Node.js including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1, an attacker can cause a Denial of Service (DoS) by establishing an HTTP or HTTPS connection in…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-5737
|
2024-11-21 13:45 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|