|
223491
|
3.5 |
LOW
Adjacent
|
microfocus
|
solutions_business_manager
|
Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to information disclosure.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2019-18947
|
2024-11-21 13:33 |
2021-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223492
|
4.8 |
MEDIUM
Adjacent
|
microfocus
|
solutions_business_manager
|
Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to session fixation.
|
CWE-384
Session Fixation
|
CVE-2019-18946
|
2024-11-21 13:33 |
2021-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223493
|
8.0 |
HIGH
Adjacent
|
microfocus
|
solutions_business_manager
|
Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to privilege escalation vulnerability.
|
NVD-CWE-noinfo
|
CVE-2019-18945
|
2024-11-21 13:33 |
2021-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223494
|
4.8 |
MEDIUM
Adjacent
|
microfocus
|
solutions_business_manager
|
Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to reflected XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-18944
|
2024-11-21 13:33 |
2021-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223495
|
8.0 |
HIGH
Adjacent
|
microfocus
|
solutions_business_manager
|
Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to XML External Entity Processing (XXE) on certain operations.
|
CWE-611
XXE
|
CVE-2019-18943
|
2024-11-21 13:33 |
2021-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223496
|
4.8 |
MEDIUM
Adjacent
|
microfocus
|
solutions_business_manager
|
Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to stored XSS. The application reflects previously stored user input without encoding.
|
CWE-79
Cross-site Scripting
|
CVE-2019-18942
|
2024-11-21 13:33 |
2021-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223497
|
7.8 |
HIGH
Local
|
autotrace_project fedoraproject
|
autotrace fedora
|
A bitmap double free in main.c in autotrace 0.31.1 allows attackers to cause an unspecified impact via a malformed bitmap image. This may occur after the use-after-free in CVE-2017-9182.
|
CWE-415
Double Free
|
CVE-2019-19005
|
2024-11-21 13:33 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223498
|
3.3 |
LOW
Local
|
autotrace_project fedoraproject
|
autotrace fedora
|
A biWidth*biBitCnt integer overflow in input-bmp.c in autotrace 0.31.1 allows attackers to provide an unexpected input value to malloc via a malformed bitmap image.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-19004
|
2024-11-21 13:33 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223499
|
9.8 |
CRITICAL
Network
|
sparkdevnetwork
|
rock_rms
|
Rock RMS versions before 8.10 and versions 9.0 through 9.3 fails to properly validate files uploaded in the application. The only protection mechanism is a file-extension blacklist that can be bypass…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-18643
|
2024-11-21 13:33 |
2021-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223500
|
9.8 |
CRITICAL
Network
|
sparkdevnetwork
|
rock_rms
|
Rock RMS version before 8.6 is vulnerable to account takeover by tampering with the user ID parameter in the profile update feature. The lack of validation and use of sequential user IDs allows any u…
|
NVD-CWE-noinfo
|
CVE-2019-18642
|
2024-11-21 13:33 |
2021-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|