|
223621
|
9.8 |
CRITICAL
Network
|
eclipse
|
vert.x
|
In Eclipse Vert.x 3.4.x up to 3.9.4, 4.0.0.milestone1, 4.0.0.milestone2, 4.0.0.milestone3, 4.0.0.milestone4, 4.0.0.milestone5, 4.0.0.Beta1, 4.0.0.Beta2, and 4.0.0.Beta3, StaticHandler doesn't correct…
|
CWE-22
Path Traversal
|
CVE-2019-17640
|
2024-11-21 13:32 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223622
|
9.8 |
CRITICAL
Network
|
jfrog
|
artifactory
|
Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely …
|
CWE-521
Weak Password Requirements
|
CVE-2019-17444
|
2024-11-21 13:32 |
2020-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223623
|
8.1 |
HIGH
Network
|
tibco
|
silver_fabric
|
The VirtualRouter component of TIBCO Software Inc.'s TIBCO Silver Fabric contains a vulnerability that theoretically allows an attacker to inject scripts via URLs. The attacker could theoretically so…
|
NVD-CWE-noinfo
|
CVE-2019-17339
|
2024-11-21 13:32 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223624
|
5.3 |
MEDIUM
Network
|
eclipse
|
openj9
|
In Eclipse OpenJ9 prior to version 0.21 on Power platforms, calling the System.arraycopy method with a length longer than the length of the source or destination array can, in certain specially craft…
|
CWE-843
Type Confusion
|
CVE-2019-17639
|
2024-11-21 13:32 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223625
|
7.1 |
HIGH
Local
|
eclipse debian
|
web_tools_platform debian_linux
|
In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote serve…
|
CWE-611
XXE
|
CVE-2019-17637
|
2024-11-21 13:32 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223626
|
9.4 |
CRITICAL
Network
|
eclipse
|
jetty
|
In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce an HTTP 431 error. When this happens, the ByteBuffer conta…
|
CWE-672
Operation on a Resource after Expiration or Release
|
CVE-2019-17638
|
2024-11-21 13:32 |
2020-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223627
|
4.6 |
MEDIUM
Physics
|
biotronik
|
cardiomessenger_ii-s_gsm_firmware cardiomessenger_ii-s_t-line_firmware
|
BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverable format. An attacker with physical access to the CardioMessenger can use thes…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-18256
|
2024-11-21 13:32 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223628
|
4.6 |
MEDIUM
Physics
|
biotronik
|
cardiomessenger_ii-s_gsm_firmware cardiomessenger_ii-s_t-line_firmware
|
BIOTRONIK CardioMessenger II, The affected products do not encrypt sensitive information while at rest. An attacker with physical access to the CardioMessenger can disclose medical measurement data a…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2019-18254
|
2024-11-21 13:32 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223629
|
4.3 |
MEDIUM
Adjacent
|
biotronik
|
cardiomessenger_ii-s_gsm_firmware cardiomessenger_ii-s_t-line_firmware
|
BIOTRONIK CardioMessenger II, The affected products allow credential reuse for multiple authentication purposes. An attacker with adjacent access to the CardioMessenger can disclose its credentials u…
|
CWE-287
Improper Authentication
|
CVE-2019-18252
|
2024-11-21 13:32 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223630
|
4.3 |
MEDIUM
Adjacent
|
biotronik
|
cardiomessenger_ii-s_gsm_firmware cardiomessenger_ii-s_t-line_firmware
|
BIOTRONIK CardioMessenger II, The affected products transmit credentials in clear-text prior to switching to an encrypted communication channel. An attacker can disclose the product’s client credenti…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-18248
|
2024-11-21 13:32 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|