|
218741
|
7.8 |
HIGH
Local
|
hornerautomation
|
cscape
|
Cscape, 9.80 SP4 and prior. An improper input validation vulnerability may be exploited by processing specially crafted POC files. This may allow an attacker to read confidential information and remo…
|
CWE-20
Improper Input Validation
|
CVE-2019-6555
|
2024-11-21 13:46 |
2019-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218742
|
6.1 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager
|
Cross-site scripting (XSS) vulnerability in F5 BIG-IP Access Policy Manager (APM) 11.5.x and 11.6.x Admin Web UI.
|
CWE-79
Cross-site Scripting
|
CVE-2019-6595
|
2024-11-21 13:46 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218743
|
5.9 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager big-ip_local_traffic_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_security_manager big-ip_domain_name_system big-ip_edge…
|
On BIG-IP 11.5.1-11.6.3.2, 12.1.3.4-12.1.3.7, 13.0.0 HF1-13.1.1.1, and 14.0.0-14.0.0.2, Multi-Path TCP (MPTCP) does not protect against multiple zero length DATA_FINs in the reassembly queue, which c…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-6594
|
2024-11-21 13:46 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218744
|
5.9 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager big-ip_local_traffic_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_security_manager big-ip_domain_name_system big-ip_edge…
|
On BIG-IP 11.5.1-11.5.4, 11.6.1, and 12.1.0, a virtual server configured with a Client SSL profile may be vulnerable to a chosen ciphertext attack against CBC ciphers. When exploited, this may result…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-6593
|
2024-11-21 13:46 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218745
|
9.1 |
CRITICAL
Network
|
f5
|
big-ip_access_policy_manager big-ip_local_traffic_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_security_manager big-ip_domain_name_system big-ip_edge…
|
On BIG-IP 14.1.0-14.1.0.1, TMM may restart and produce a core file when validating SSL certificates in client SSL or server SSL profiles.
|
CWE-295
Improper Certificate Validation
|
CVE-2019-6592
|
2024-11-21 13:46 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218746
|
9.8 |
CRITICAL
Network
|
cordaware
|
bestinformed
|
Cordaware bestinformed Microsoft Windows client before 6.2.1.0 is affected by insecure SSL certificate verification and insecure access patterns. These issues allow remote attackers to downgrade encr…
|
CWE-295
Improper Certificate Validation
|
CVE-2019-6266
|
2024-11-21 13:46 |
2019-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218747
|
7.8 |
HIGH
Local
|
cordaware
|
bestinformed
|
The Scripting and AutoUpdate functionality in Cordaware bestinformed Microsoft Windows client versions before 6.2.1.0 are affected by insecure implementations which allow remote attackers to execute …
|
NVD-CWE-noinfo
|
CVE-2019-6265
|
2024-11-21 13:46 |
2019-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218748
|
5.9 |
MEDIUM
Network
|
citrix
|
netscaler_gateway_firmware netscaler_application_delivery_controller_firmware
|
Citrix NetScaler Gateway 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 and Application Delivery Controller (ADC) 12.1 b…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-6485
|
2024-11-21 13:46 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218749
|
8.1 |
HIGH
Network
|
drupal
|
drupal
|
Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-6340
|
2024-11-21 13:46 |
2019-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218750
|
8.1 |
HIGH
Network
|
mirc
|
mirc
|
mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The attacker can specify an irc:// URI that loads an arbitrary .ini file from a UNC …
|
CWE-88
Argument Injection
|
CVE-2019-6453
|
2024-11-21 13:46 |
2019-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|