|
218511
|
6.4 |
MEDIUM
Local
|
lenovo
|
510-15ikl_firmware 510s-08ikl_firmware ideacentre_300-20ish_firmware ideacentre_300s-11ish_firmware ideacentre_310s-08asr_firmware ideacentre_310s-08igm_firmware ideacentre_510-15ic…
|
A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution.
|
NVD-CWE-noinfo
|
CVE-2019-6170
|
2024-11-21 13:46 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218512
|
5.2 |
MEDIUM
Physics
|
hp
|
d9l63a_firmware d9l64a_firmware t0g70a_firmware j3p65a_firmware j3p68a_firmware j6u57a_firmware j6u57b_firmware j9v80a_firmware j9v80b_firmware j6u55a_firmware j6u55d_fi…
|
For the printers listed a maliciously crafted print file might cause certain HP Inkjet printers to assert. Under certain circumstances, the printer produces a core dump to a local device.
|
NVD-CWE-noinfo
|
CVE-2019-6337
|
2024-11-21 13:46 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218513
|
6.1 |
MEDIUM
Network
|
forcepoint
|
email_security security_manager
|
It has been reported that XSS is possible in Forcepoint Email Security, versions 8.5 and 8.5.3. It is strongly recommended that you apply the relevant hotfix in order to remediate this issue.
|
CWE-79
Cross-site Scripting
|
CVE-2019-6142
|
2024-11-21 13:46 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218514
|
7.5 |
HIGH
Network
|
isc redhat opensuse
|
dhcpd bind enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server leap
|
There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its…
|
NVD-CWE-noinfo
|
CVE-2019-6470
|
2024-11-21 13:46 |
2019-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218515
|
4.3 |
MEDIUM
Network
|
f5
|
big-ip_advanced_firewall_manager
|
On BIG-IP AFM 15.0.0-15.0.1, 14.0.0-14.1.2, 13.1.0-13.1.3.1, and 12.1.0-12.1.5, a vulnerability in the AFM configuration utility may allow any authenticated BIG-IP user to run an SQL injection attack.
|
CWE-89
SQL Injection
|
CVE-2019-6658
|
2024-11-21 13:46 |
2019-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218516
|
6.1 |
MEDIUM
Network
|
f5
|
big-ip_advanced_firewall_manager big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_analytics big-ip_access_policy_manager big-ip_edge_gateway big-ip_domain…
|
On BIG-IP 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Interface (TMUI…
|
CWE-79
Cross-site Scripting
|
CVE-2019-6657
|
2024-11-21 13:46 |
2019-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218517
|
7.8 |
HIGH
Local
|
fortinet
|
forticlient
|
A malicious DLL preload vulnerability in Fortinet FortiClient for Windows 6.2.0 and below allows a privileged attacker to perform arbitrary code execution via forging that DLL.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-6692
|
2024-11-21 13:46 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218518
|
6.5 |
MEDIUM
Network
|
forcepoint
|
one_endpoint
|
This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP and Web protection.
|
CWE-863
Incorrect Authorization
|
CVE-2019-6144
|
2024-11-21 13:46 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218519
|
7.5 |
HIGH
Network
|
isc
|
bind
|
A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder returns a referral rather than resolving the query. This affects BIND versions 9.…
|
CWE-617
Reachable Assertion
|
CVE-2019-6476
|
2024-11-21 13:46 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218520
|
7.5 |
HIGH
Network
|
isc
|
bind
|
Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers. A mirror zone is similar to a zone of type secondary, except that its data is subject to D…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-6475
|
2024-11-21 13:46 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|