|
219641
|
5.4 |
MEDIUM
Network
|
redhat
|
jboss_enterprise_application_platform single_sign-on
|
It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. An attacker could use this to send a malicious scr…
|
CWE-79
Cross-site Scripting
|
CVE-2019-3872
|
2024-11-21 13:42 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219642
|
4.8 |
MEDIUM
Network
|
redhat
|
single_sign-on keycloak
|
A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRL, where the CRL list can be obtained from the URL provided …
|
CWE-295
Improper Certificate Validation
|
CVE-2019-3875
|
2024-11-21 13:42 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219643
|
5.4 |
MEDIUM
Network
|
zte
|
netnumen_dap_firmware
|
All versions up to V20.18.40.R7.B1of ZTE NetNumen DAP product have an XSS vulnerability. Due to the lack of correct validation of client data in WEB applications, which results in users being hijacke…
|
CWE-79
Cross-site Scripting
|
CVE-2019-3413
|
2024-11-21 13:42 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219644
|
9.8 |
CRITICAL
Network
|
zte
|
mf920_firmware
|
All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by command execution vulnerability. Due to some interfaces do not adequately verify parameters, an attacker can execute arbitrary comm…
|
CWE-78
OS Command
|
CVE-2019-3412
|
2024-11-21 13:42 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219645
|
7.5 |
HIGH
Network
|
zte
|
mf920_firmware
|
All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by information leak vulnerability. Due to some interfaces can obtain the WebUI login password without login, an attacker can exploit t…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-3411
|
2024-11-21 13:42 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219646
|
8.8 |
HIGH
Network
|
zte
|
wf820\+_lte_outdoor_cpe_firmware
|
All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by Cross-Site Request Forgery vulnerability,which stems from the fact that WEB applications do not adequatel…
|
CWE-352
Origin Validation Error
|
CVE-2019-3410
|
2024-11-21 13:42 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219647
|
8.8 |
HIGH
Network
|
zte
|
wf820\+_lte_outdoor_cpe_firmware
|
All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by command injection vulnerability. Due to inadequate parameter verification, unauthorized users can take ad…
|
CWE-78
OS Command
|
CVE-2019-3409
|
2024-11-21 13:42 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219648
|
7.4 |
HIGH
Network
|
solarwinds
|
dameware_mini_remote_control
|
Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating RsaSignatureLen during key negotiation, which co…
|
CWE-20 CWE-125
Improper Input Validation Out-of-bounds Read
|
CVE-2019-3957
|
2024-11-21 13:42 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219649
|
7.4 |
HIGH
Network
|
dameware
|
remote_mini_control
|
Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating CltDHPubKeyLen during key negotiation, which cou…
|
CWE-20 CWE-125
Improper Input Validation Out-of-bounds Read
|
CVE-2019-3956
|
2024-11-21 13:42 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219650
|
7.5 |
HIGH
Network
|
dameware
|
remote_mini_control
|
Dameware Remote Mini Control version 12.1.0.34 and prior contains a unauthenticated remote heap overflow due to the server not properly validating RsaPubKeyLen during key negotiation. An unauthentica…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-3955
|
2024-11-21 13:42 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|