|
219391
|
8.8 |
HIGH
Network
|
accusoft
|
imagegear
|
An exploitable out-of-bounds write vulnerability exists in the TIFreadstripdata function of the igcore19d.dll library of Accusoft ImageGear 19.5.0. A specially crafted TIFF file file can cause an out…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-5187
|
2024-11-21 13:44 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219392
|
7.5 |
HIGH
Network
|
arubanetworks
|
5400r_firmware 3810_firmware 2920_firmware 2930_firmware 2530_with_gigt_port_firmware 2530_10\/100_port_firmware 2540_firmware
|
A remotely exploitable information disclosure vulnerability is present in Aruba Intelligent Edge Switch models 5400, 3810, 2920, 2930, 2530 with GigT port, 2530 10/100 port, or 2540. The vulnerabilit…
|
NVD-CWE-noinfo
|
CVE-2019-5322
|
2024-11-21 13:44 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219393
|
5.3 |
MEDIUM
Network
|
ibm
|
content_navigator
|
IBM Content Navigator 3.0CD is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to netwo…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-4741
|
2024-11-21 13:44 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219394
|
6.5 |
MEDIUM
Local
|
ibm
|
sdk websphere_application_server
|
IBM SDK, Java Technology Edition Version 7.0.0.0 through 7.0.10.55, 7.1.0.0 through 7.1.4.55, and 8.0.0.0 through 8.0.6.0 could allow a local authenticated attacker to execute arbitrary code on the s…
|
CWE-426
Untrusted Search Path
|
CVE-2019-4732
|
2024-11-21 13:44 |
2020-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219395
|
7.5 |
HIGH
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to caus…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-4720
|
2024-11-21 13:44 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219396
|
7.1 |
HIGH
Network
|
ibm
|
security_access_manager
|
IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sen…
|
CWE-611
XXE
|
CVE-2019-4707
|
2024-11-21 13:44 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219397
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboard which could result in disclosure of vulnerability feedback information.
|
CWE-862
Missing Authorization
|
CVE-2019-5470
|
2024-11-21 13:44 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219398
|
8.8 |
HIGH
Network
|
gitlab
|
gitlab
|
An privilege escalation issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 when Mattermost slash commands are used with a blocked account.
|
CWE-269
Improper Privilege Management
|
CVE-2019-5468
|
2024-11-21 13:44 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219399
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new merge requests endpoint to disclose label names.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-5466
|
2024-11-21 13:44 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219400
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which could result in disclosure of the newly created issue ID.
|
NVD-CWE-noinfo
|
CVE-2019-5465
|
2024-11-21 13:44 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|