|
225361
|
9.0 |
CRITICAL
Network
|
dell
|
xtremio_management_server
|
Dell EMC XtremIO XMS versions prior to 6.3.0 contain a stored cross-site scripting vulnerability. A low-privileged malicious remote user of XtremIO may exploit this vulnerability to store malicious H…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18578
|
2024-11-21 13:33 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225362
|
6.7 |
MEDIUM
Local
|
dell
|
xtremio_management_server
|
Dell EMC XtremIO XMS versions prior to 6.3.0 contain an incorrect permission assignment vulnerability. A malicious local user with XtremIO xinstall privileges may exploit this vulnerability to gain r…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-18577
|
2024-11-21 13:33 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225363
|
6.7 |
MEDIUM
Local
|
dell
|
xtremio_management_server
|
Dell EMC XtremIO XMS versions prior to 6.3.0 contain an information disclosure vulnerability where OS users’ passwords are logged in local files. Malicious local users with access to the log files ma…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-18576
|
2024-11-21 13:33 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225364
|
7.5 |
HIGH
Network
|
siemens
|
simatic_s7-300_cpu_firmware simatic_s7-300_cpu_312_ifm_firmware simatic_s7-300_cpu_313_firmware simatic_s7-300_cpu_314_firmware simatic_s7-300_cpu_314_ifm_firmware simatic_s7-300_cpu_3…
|
A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions < V3.X.17), SIMATIC TDC CP51M1 (All versions < V1.1.8), SIMATIC TDC CPU55…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-18336
|
2024-11-21 13:33 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225365
|
5.9 |
MEDIUM
Network
|
mitel
|
6863i_firmware 6865i_firmware 6867i_firmware 6869i_firmware 6873i_firmware 6920_firmware 6930_firmware 6940_firmware
|
A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versions 5.1.0.2051 SP2 and earlier, could allow an attacker to launch a man-in-the-…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2019-18863
|
2024-11-21 13:33 |
2020-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225366
|
9.8 |
CRITICAL
Network
|
suse opensuse
|
linux_enterprise_server leap
|
A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remote attackers to cause DoS or potentially code exec…
|
CWE-416
Use After Free
|
CVE-2019-18903
|
2024-11-21 13:33 |
2020-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225367
|
9.8 |
CRITICAL
Network
|
suse opensuse
|
linux_enterprise_server leap
|
A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remote attackers to cause DoS or potentially code exec…
|
CWE-416
Use After Free
|
CVE-2019-18902
|
2024-11-21 13:33 |
2020-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225368
|
5.5 |
MEDIUM
Local
|
suse opensuse
|
linux_enterprise_server leap
|
A UNIX Symbolic Link (Symlink) Following vulnerability in the mysql-systemd-helper of the mariadb packaging of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allows local attackers …
|
-
|
CVE-2019-18901
|
2024-11-21 13:33 |
2020-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225369
|
7.8 |
HIGH
Local
|
suse opensuse
|
linux_enterprise_server leap
|
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Factory allows local attackers to escalat…
|
-
|
CVE-2019-18897
|
2024-11-21 13:33 |
2020-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225370
|
5.0 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite through 7.10.2 allows SSRF.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-18846
|
2024-11-21 13:33 |
2020-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|