|
224021
|
9.8 |
CRITICAL
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-18364
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224022
|
5.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2019.1.2, access could be gained to the history of builds of a deleted build configuration under some circumstances.
|
NVD-CWE-noinfo
|
CVE-2019-18363
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224023
|
5.3 |
MEDIUM
Network
|
jetbrains
|
mps
|
JetBrains MPS before 2019.2.2 exposed listening ports to the network.
|
NVD-CWE-noinfo
|
CVE-2019-18362
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224024
|
5.3 |
MEDIUM
Local
|
jetbrains
|
intellij_idea
|
JetBrains IntelliJ IDEA before 2019.2 allows local user privilege escalation, potentially leading to arbitrary code execution.
|
NVD-CWE-noinfo
|
CVE-2019-18361
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224025
|
5.3 |
MEDIUM
Network
|
jetbrains
|
hub
|
In JetBrains Hub versions earlier than 2019.1.11738, username enumeration was possible through password recovery.
|
NVD-CWE-noinfo
|
CVE-2019-18360
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224026
|
9.8 |
CRITICAL
Network
|
xen debian fedoraproject opensuse
|
xen debian_linux fedora leap
|
An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. There is missing descriptor table limit checking in x8…
|
CWE-269
Improper Privilege Management
|
CVE-2019-18425
|
2024-11-21 13:33 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224027
|
6.8 |
MEDIUM
Physics
|
xen debian fedoraproject opensuse
|
xen debian_linux fedora leap
|
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device. This occurs because passe…
|
CWE-78
OS Command
|
CVE-2019-18424
|
2024-11-21 13:33 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224028
|
8.8 |
HIGH
Network
|
xen debian fedoraproject
|
xen debian_linux fedora
|
An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service via a XENMEM_add_to_physmap hypercall. p2m->max_mapped_gfn is used by the functions p2m_resolve_…
|
CWE-193
Off-by-one Error
|
CVE-2019-18423
|
2024-11-21 13:33 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224029
|
5.5 |
MEDIUM
Local
|
totaldefense
|
anti-virus
|
The quarantine restoration function in Total Defense Anti-virus 11.5.2.28 is vulnerable to symbolic link attacks, allowing files to be written to privileged directories.
|
CWE-59
Link Following
|
CVE-2019-18645
|
2024-11-21 13:33 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224030
|
8.8 |
HIGH
Network
|
xen debian fedoraproject
|
xen debian_linux fedora
|
An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service or gain privileges by leveraging the erroneous enabling of interrupts. Interrupts are unconditio…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-18422
|
2024-11-21 13:33 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|