|
223281
|
7.1 |
HIGH
Network
|
hitachienergy
|
asset_suite
|
Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables full access to directly referenced objects. An at…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-18998
|
2024-11-21 13:33 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223282
|
5.4 |
MEDIUM
Network
|
lexmark
|
cx31x_firmware cx41x_firmware cx310_firmware ms310_firmware ms312_firmware ms317_firmware ms410_firmware m1140_firmware ms315_firmware ms415_firmware ms417_firmware m…
|
Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and ot…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18791
|
2024-11-21 13:33 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223283
|
7.8 |
HIGH
Local
|
hp
|
system_event_utility
|
A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version 1.4.33. This vulnerability may allow a local attacker to execute arbitrary cod…
|
CWE-428
Unquoted Search Path or Element
|
CVE-2019-18915
|
2024-11-21 13:33 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223284
|
7.0 |
HIGH
Local
|
teamviewer
|
teamviewer
|
TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' installations. It used a shared AES key for all installations…
|
CWE-521
Weak Password Requirements
|
CVE-2019-18988
|
2024-11-21 13:33 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223285
|
6.3 |
MEDIUM
Local
|
hp
|
bromium
|
Bromium client version 4.0.3.2060 and prior to 4.1.7 Update 1 has an out of bound read results in race condition causing Kernel memory leaks or denial of service.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-18567
|
2024-11-21 13:33 |
2020-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223286
|
6.8 |
MEDIUM
Physics
|
hp
|
elitedesk_800_g5_dm_firmware elitedesk_800_g5_sff_firmware elitedesk_800_g5_twr_firmware eliteone_800_g5_aio_firmware prodesk_400_g5_dm_firmware prodesk_400_g6_mt_firmware prodesk_4…
|
A potential security vulnerability with pre-boot DMA may allow unauthorized UEFI code execution using open-case attacks. This industry-wide issue requires physically accessing internal expansion slot…
|
NVD-CWE-noinfo
|
CVE-2019-18913
|
2024-11-21 13:33 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223287
|
7.8 |
HIGH
Local
|
sudo_project debian
|
sudo debian_linux
|
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and ele…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-18634
|
2024-11-21 13:33 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223288
|
3.3 |
LOW
Local
|
opensuse
|
libzypp
|
: Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allowed local attackers to read a cookie store use…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-18900
|
2024-11-21 13:33 |
2020-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223289
|
5.5 |
MEDIUM
Local
|
apt-cacher-ng_project opensuse
|
apt-cacher-ng backports
|
The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt-cacher-ng with root privileges. This can allow local attackers to influence the outcome of these opera…
|
-
|
CVE-2019-18899
|
2024-11-21 13:33 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223290
|
7.8 |
HIGH
Local
|
suse opensuse
|
trousers leap
|
UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root…
|
-
|
CVE-2019-18898
|
2024-11-21 13:33 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|