|
218861
|
7.8 |
HIGH
Local
|
a-pdf
|
wav_to_mp3
|
A-PDF WAV to MP3 version 1.0.0 suffers from an instance of CWE-121: Stack-based Buffer Overflow.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-5618
|
2024-11-21 13:45 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218862
|
9.8 |
CRITICAL
Network
|
freebsd netapp
|
freebsd clustered_data_ontap
|
In FreeBSD 12.1-STABLE before r356035, 12.1-RELEASE before 12.1-RELEASE-p4, 11.3-STABLE before r356036, and 11.3-RELEASE before 11.3-RELEASE-p8, incomplete packet data validation may result in access…
|
CWE-119 CWE-20
Incorrect Access of Indexable Resource ('Range Error') Improper Input Validation
|
CVE-2019-5614
|
2024-11-21 13:45 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218863
|
7.8 |
HIGH
Local
|
vmware
|
horizon_client remote_console workstation
|
For VMware Horizon Client for Windows (5.x and prior before 5.3.0), VMware Remote Console for Windows (10.x before 11.0.0), VMware Workstation for Windows (15.x before 15.5.2) the folder containing c…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-5543
|
2024-11-21 13:45 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218864
|
6.5 |
MEDIUM
Network
|
barracuda
|
load_balancer_adc_firmware
|
Authenticated, administrative access to a Barracuda Load Balancer ADC running unpatched firmware <= v6.4 allows one to edit the LDAP service configuration of the balancer and change the LDAP server t…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-5648
|
2024-11-21 13:45 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218865
|
9.8 |
CRITICAL
Network
|
freebsd
|
freebsd
|
In FreeBSD 12.0-RELEASE before 12.0-RELEASE-p13, a missing check in the ipsec packet processor allows reinjection of an old packet to be accepted by the ipsec endpoint. Depending on the higher-level …
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-5613
|
2024-11-21 13:45 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218866
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions.
|
CWE-863
Incorrect Authorization
|
CVE-2019-5474
|
2024-11-21 13:45 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218867
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epic comments.
|
NVD-CWE-Other CWE-269
Improper Privilege Management
|
CVE-2019-5472
|
2024-11-21 13:45 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218868
|
6.1 |
MEDIUM
Network
|
f-revocrm
|
f-revocrm
|
Cross-site scripting vulnerability in F-RevoCRM 6.0 to F-RevoCRM 6.5 patch6 (version 6 series) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2019-6036
|
2024-11-21 13:45 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218869
|
5.5 |
MEDIUM
Local
|
fortinet
|
fortios
|
Improper permission or value checking in the CLI console may allow a non-privileged user to obtain Fortinet FortiOS plaint text private keys of system's builtin local certificates via unsetting the k…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2019-5593
|
2024-11-21 13:45 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218870
|
7.1 |
HIGH
Local
|
rapid7
|
appspider
|
The Chrome Plugin for Rapid7 AppSpider can incorrectly keep browser sessions active after recording a macro, even after a restart of the Chrome browser. This behavior could make future session hijack…
|
CWE-613
Insufficient Session Expiration
|
CVE-2019-5647
|
2024-11-21 13:45 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|