|
218831
|
8.8 |
HIGH
Local
|
vmware
|
workstation
|
VMware Workstation (15.x before 15.1.0) contains a use-after-free vulnerability in the Advanced Linux Sound Architecture (ALSA) backend. A malicious user with normal user privileges on the guest mach…
|
CWE-416
Use After Free
|
CVE-2019-5525
|
2024-11-21 13:45 |
2019-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218832
|
7.1 |
HIGH
Local
|
vmware
|
tools
|
VMware Tools for Windows update addresses an out of bounds read vulnerability in vm3dmp driver which is installed with vmtools in Windows guest machines. This issue is present in versions 10.2.x and …
|
CWE-125
Out-of-bounds Read
|
CVE-2019-5522
|
2024-11-21 13:45 |
2019-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218833
|
6.1 |
MEDIUM
Network
|
fortinet
|
fortios
|
A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4 under SSL VPN web portal may allow an attacker to execute unauthorized malicious script code via the "err" para…
|
CWE-79
Cross-site Scripting
|
CVE-2019-5588
|
2024-11-21 13:45 |
2019-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218834
|
6.5 |
MEDIUM
Network
|
fortinet
|
fortios
|
Lack of root file system integrity checking in Fortinet FortiOS VM application images all versions below 6.0.5 may allow attacker to implant malicious programs into the installing image by reassembli…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-5587
|
2024-11-21 13:45 |
2019-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218835
|
6.1 |
MEDIUM
Network
|
fortinet
|
fortios
|
A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.2.0 to 5.6.10, 6.0.0 to 6.0.4 under SSL VPN web portal may allow an attacker to execute unauthorized malicious script code v…
|
CWE-79
Cross-site Scripting
|
CVE-2019-5586
|
2024-11-21 13:45 |
2019-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218836
|
7.8 |
HIGH
Local
|
nvidia
|
geforce_experience
|
NVIDIA GeForce Experience versions prior to 3.19 contains a vulnerability in the Web Helper component, in which an attacker with local system access can craft input that may not be properly validated…
|
CWE-20
Improper Input Validation
|
CVE-2019-5678
|
2024-11-21 13:45 |
2019-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218837
|
7.8 |
HIGH
Local
|
fortinet
|
forticlient
|
An Unsafe Search Path vulnerability in FortiClient Online Installer (Windows version before 6.0.6) may allow an unauthenticated, remote attacker with control over the directory in which FortiClientOn…
|
CWE-426
Untrusted Search Path
|
CVE-2019-5589
|
2024-11-21 13:45 |
2019-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218838
|
5.5 |
MEDIUM
Local
|
google opensuse
|
chrome leap backports
|
Incorrect command line processing in Chrome in Google Chrome prior to 73.0.3683.75 allowed a local attacker to perform domain spoofing via a crafted domain name.
|
CWE-88
Argument Injection
|
CVE-2019-5804
|
2024-11-21 13:45 |
2019-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218839
|
6.5 |
MEDIUM
Network
|
google opensuse
|
chrome leap backports
|
Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
|
CWE-20
Improper Input Validation
|
CVE-2019-5803
|
2024-11-21 13:45 |
2019-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218840
|
6.5 |
MEDIUM
Network
|
google opensuse
|
chrome leap backports_sle
|
Incorrect handling of download origins in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
|
NVD-CWE-noinfo
|
CVE-2019-5802
|
2024-11-21 13:45 |
2019-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|