Show filters
161 Total Results
Displaying 31-40 of 161
Sort by:
Attacker Value
Unknown
CVE-2020-35498
Disclosure Date: February 11, 2021 (last updated November 08, 2023)
A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the resulting megaflow in the kernel to be too wide, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
0
Attacker Value
Unknown
CVE-2020-11073
Disclosure Date: May 13, 2020 (last updated November 27, 2024)
In Autoswitch Python Virtualenv before version 0.16.0, a user who enters a directory with a malicious `.venv` file could run arbitrary code without any user interaction. This is fixed in version: 1.16.0
0
Attacker Value
Unknown
CVE-2019-19632
Disclosure Date: January 24, 2020 (last updated February 21, 2025)
An issue was discovered in Big Switch Big Monitoring Fabric 6.2 through 6.2.4, 6.3 through 6.3.9, 7.0 through 7.0.3, and 7.1 through 7.1.3; Big Cloud Fabric 4.5 through 4.5.5, 4.7 through 4.7.7, 5.0 through 5.0.1, and 5.1 through 5.1.4; and Multi-Cloud Director through 1.1.0. An unauthenticated attacker may inject stored arbitrary JavaScript (XSS), and execute it in the content of authenticated administrators.
0
Attacker Value
Unknown
CVE-2019-19492
Disclosure Date: December 02, 2019 (last updated November 27, 2024)
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
0
Attacker Value
Unknown
CVE-2019-18465
Disclosure Date: October 31, 2019 (last updated November 27, 2024)
In Progress MOVEit Transfer 11.1 before 11.1.3, a vulnerability has been found that could allow an attacker to sign in without full credentials via the SSH (SFTP) interface. The vulnerability affects only certain SSH (SFTP) configurations, and is applicable only if the MySQL database is being used.
0
Attacker Value
Unknown
CVE-2019-18464
Disclosure Date: October 31, 2019 (last updated November 27, 2024)
In Progress MOVEit Transfer 10.2 before 10.2.6 (2018.3), 11.0 before 11.0.4 (2019.0.4), and 11.1 before 11.1.3 (2019.1.3), multiple SQL Injection vulnerabilities have been found in the REST API that could allow an unauthenticated attacker to gain unauthorized access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database or may be able to alter the database.
0
Attacker Value
Unknown
CVE-2019-16383
Disclosure Date: September 24, 2019 (last updated November 27, 2024)
MOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 allows an unauthenticated attacker to gain unauthorized access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, or may be able to alter the database via the REST API, aka SQL Injection.
0
Attacker Value
Unknown
CVE-2019-19631
Disclosure Date: August 28, 2019 (last updated February 21, 2025)
An issue was discovered in Big Switch Big Monitoring Fabric 6.2 through 6.2.4, 6.3 through 6.3.9, 7.0 through 7.0.3, and 7.1 through 7.1.3; Big Cloud Fabric 4.5 through 4.5.5, 4.7 through 4.7.7, 5.0 through 5.0.1, and 5.1 through 5.1.4; and Multi-Cloud Director through 1.1.0. A read-only user can access sensitive information via an API endpoint that reveals session cookies of authenticated administrators, leading to privilege escalation.
0
Attacker Value
Unknown
CVE-2019-12145
Disclosure Date: June 11, 2019 (last updated November 27, 2024)
A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. An attacker can supply a string using special patterns via the SCP protocol to disclose path names on the host operating system.
0
Attacker Value
Unknown
CVE-2019-12146
Disclosure Date: June 11, 2019 (last updated November 27, 2024)
A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. Attackers have the ability to abuse a flaw in the SCP listener by crafting strings using specific patterns to write files and create directories outside of their authorized directory.
0