|
221511
|
7.5 |
HIGH
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_link_controller big-ip_policy_enforcement_manager big-ip_webaccelerator …
|
On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.1.0-13.1.1.5, 12.1.0-12.1.4.1, and 11.5.1-11.6.5, under certain conditions, TMM may consume excessive resources when processing traffic f…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-6667
|
2024-11-21 13:46 |
2019-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221512
|
7.5 |
HIGH
Network
|
f5
|
big-ip_access_policy_manager big-ip_global_traffic_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_link_controller big-ip_policy_enforcement_man…
|
On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, and 13.1.0-13.1.1.4, the TMM process may produce a core file when an upstream server or cache sends the BIG-IP an invalid age header value.
|
NVD-CWE-noinfo
|
CVE-2019-6666
|
2024-11-21 13:46 |
2019-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221513
|
7.5 |
HIGH
Network
|
isc fedoraproject
|
bind fedora
|
With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without pipelining enabled. A client using a TCP-pipeline…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-6477
|
2024-11-21 13:46 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221514
|
9.8 |
CRITICAL
Network
|
f5
|
big-ip_link_controller big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_fraud_protection…
|
BIG-IP configurations using Active Directory, LDAP, or Client Certificate LDAP for management authentication with multiple servers are exposed to a vulnerability which allows an authentication bypass…
|
CWE-287
Improper Authentication
|
CVE-2019-6675
|
2024-11-21 13:46 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221515
|
6.5 |
MEDIUM
Network
|
fortinet
|
fortios
|
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-6693
|
2024-11-21 13:46 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221516
|
7.8 |
HIGH
Local
|
lenovo
|
paper
|
A potential vulnerability in the discontinued LenovoPaper software version 1.0.0.22 may allow local privilege escalation.
|
NVD-CWE-noinfo
|
CVE-2019-6191
|
2024-11-21 13:46 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221517
|
7.8 |
HIGH
Local
|
lenovo
|
system_interface_foundation
|
A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow an administrative user to load an unsigned DLL.
|
CWE-426
Untrusted Search Path
|
CVE-2019-6189
|
2024-11-21 13:46 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221518
|
6.5 |
MEDIUM
Network
|
lenovo
|
xclarity_controller
|
A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XC…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2019-6187
|
2024-11-21 13:46 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221519
|
8.8 |
HIGH
Network
|
lenovo
|
system_interface_foundation
|
A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow an authenticated user to execute code as another user.
|
NVD-CWE-noinfo
|
CVE-2019-6186
|
2024-11-21 13:46 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221520
|
7.8 |
HIGH
Local
|
lenovo
|
customer_engagement_service
|
A potential vulnerability in the discontinued Customer Engagement Service (CCSDK) software version 2.0.21.1 may allow local privilege escalation.
|
NVD-CWE-noinfo
|
CVE-2019-6184
|
2024-11-21 13:46 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|