Show filters
508 Total Results
Displaying 301-310 of 508
Sort by:
Attacker Value
Unknown

CVE-2019-11155

Disclosure Date: November 14, 2019 (last updated November 27, 2024)
Improper directory permissions in Intel(R) PROSet/Wireless WiFi Software before version 21.40 may allow an authenticated user to potentially enable denial of service and information disclosure via local access.
Attacker Value
Unknown

CVE-2019-11156

Disclosure Date: November 14, 2019 (last updated November 27, 2024)
Logic errors in Intel(R) PROSet/Wireless WiFi Software before version 21.40 may allow an authenticated user to potentially enable escalation of privilege, denial of service, and information disclosure via local access.
Attacker Value
Unknown

CVE-2019-11154

Disclosure Date: November 14, 2019 (last updated November 27, 2024)
Improper directory permissions in Intel(R) PROSet/Wireless WiFi Software before version 21.40 may allow an authenticated user to potentially enable denial of service and information disclosure via local access.
Attacker Value
Unknown

CVE-2019-11153

Disclosure Date: November 14, 2019 (last updated November 27, 2024)
Memory corruption issues in Intel(R) PROSet/Wireless WiFi Software extension DLL before version 21.40 may allow an authenticated user to potentially enable escalation of privilege, information disclosure and a denial of service via local access.
Attacker Value
Unknown

CVE-2019-4486

Disclosure Date: October 24, 2019 (last updated November 27, 2024)
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164070.
Attacker Value
Unknown

CVE-2019-17195

Disclosure Date: October 15, 2019 (last updated November 08, 2023)
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
Attacker Value
Unknown

CVE-2019-17426

Disclosure Date: October 10, 2019 (last updated November 27, 2024)
Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype attribute is ignored. For example, adding "_bsontype":"a" can sometimes interfere with a query filter. NOTE: this CVE is about Mongoose's failure to work around this _bsontype special case that exists in older versions of the bson parser (aka the mongodb/js-bson project).
Attacker Value
Unknown

CVE-2019-4512

Disclosure Date: October 08, 2019 (last updated November 27, 2024)
IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164554.
Attacker Value
Unknown

CVE-2019-5066

Disclosure Date: September 18, 2019 (last updated November 27, 2024)
An exploitable use-after-free vulnerability exists in the way LZW-compressed streams are processed in Aspose.PDF 19.2 for C++. A specially crafted PDF can cause a dangling heap pointer, resulting in a use-after-free condition. To trigger this vulnerability, a specifically crafted PDF document needs to be processed by the target application.
Attacker Value
Unknown

CVE-2019-5042

Disclosure Date: September 18, 2019 (last updated November 27, 2024)
An exploitable Use-After-Free vulnerability exists in the way FunctionType 0 PDF elements are processed in Aspose.PDF 19.2 for C++. A specially crafted PDF can cause a dangling heap pointer, resulting in a use-after-free. An attacker can send a malicious PDF to trigger this vulnerability.