Show filters
249 Total Results
Displaying 171-180 of 249
Sort by:
Attacker Value
Unknown

CVE-2019-15040

Disclosure Date: October 02, 2019 (last updated November 27, 2024)
JetBrains YouTrack versions before 2019.1 had a CSRF vulnerability on the settings page.
Attacker Value
Unknown

CVE-2019-14956

Disclosure Date: October 02, 2019 (last updated November 27, 2024)
JetBrains YouTrack before 2019.2.53938 was using incorrect settings, allowing a user without necessary permissions to get other project names.
Attacker Value
Unknown

CVE-2019-15041

Disclosure Date: October 01, 2019 (last updated November 27, 2024)
JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality from an Untrusted Control Sphere.
Attacker Value
Unknown

CVE-2019-14953

Disclosure Date: October 01, 2019 (last updated November 27, 2024)
JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox browser.
Attacker Value
Unknown

CVE-2019-14952

Disclosure Date: October 01, 2019 (last updated November 27, 2024)
JetBrains YouTrack versions before 2019.1.52584 had a possible XSS in the issue titles.
Attacker Value
Unknown

CVE-2019-10082

Disclosure Date: September 26, 2019 (last updated November 08, 2023)
In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memory after being freed, during connection shutdown.
Attacker Value
Unknown

CVE-2019-10097

Disclosure Date: September 26, 2019 (last updated November 08, 2023)
In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol, a specially crafted PROXY header could trigger a stack buffer overflow or NULL pointer deference. This vulnerability could only be triggered by a trusted proxy and not by untrusted HTTP clients.
Attacker Value
Unknown

CVE-2019-9517

Disclosure Date: August 13, 2019 (last updated January 15, 2025)
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requests for a large response object. Depending on how the servers queue the responses, this can consume excess memory, CPU, or both.
Attacker Value
Unknown

CVE-2019-1020007

Disclosure Date: July 29, 2019 (last updated November 27, 2024)
Dependency-Track before 3.5.1 allows XSS.
0
Attacker Value
Unknown

CVE-2019-12852

Disclosure Date: July 03, 2019 (last updated November 27, 2024)
An SSRF attack was possible on a JetBrains YouTrack server. The issue (1 of 2) was fixed in JetBrains YouTrack 2018.4.49168.
0