Show filters
602 Total Results
Displaying 411-420 of 602
Sort by:
Attacker Value
Unknown

CVE-2019-7229

Disclosure Date: June 24, 2019 (last updated November 27, 2024)
The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilization of USB/SD Card to flash the device" and "Remote provisioning process via ABB Panel Builder 600 over FTP." Neither of these transmission methods implements any form of encryption or authenticity checks against the new firmware HMI software binary files.
Attacker Value
Unknown

CVE-2019-3735

Disclosure Date: June 20, 2019 (last updated November 27, 2024)
Dell SupportAssist for Business PCs version 2.0 and Dell SupportAssist for Home PCs version 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, and 3.2.1 contain an Improper Privilege Management Vulnerability. A malicious local user can exploit this vulnerability by inheriting a system thread using a leaked thread handle to gain system privileges on the affected machine.
Attacker Value
Unknown

CVE-2018-17389

Disclosure Date: June 19, 2019 (last updated November 27, 2024)
CSRF exists in server.php in Live Call Support Application 1.5 for adding an admin account.
0
Attacker Value
Unknown

CVE-2019-12133

Disclosure Date: June 18, 2019 (last updated November 27, 2024)
Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said products try to execute binaries such as sc.exe from the current directory upon system start. This will effectively allow non-privileged users to escalate privileges to NT AUTHORITY\SYSTEM. This affects Desktop Central 10.0.380, EventLog Analyzer 12.0.2, ServiceDesk Plus 10.0.0, SupportCenter Plus 8.1, O365 Manager Plus 4.0, Mobile Device Manager Plus 9.0.0, Patch Connect Plus 9.0.0, Vulnerability Manager Plus 9.0.0, Patch Manager Plus 9.0.0, OpManager 12.3, NetFlow Analyzer 11.0, OpUtils 11.0, Network Configuration Manager 11.0, FireWall 12.0, Key Manager Plus 5.6, Password Manager Pro 9.9, Analytics Plus 1.0, and Browser Security Plus.
0
Attacker Value
Unknown

CVE-2019-5436

Disclosure Date: May 28, 2019 (last updated November 08, 2023)
A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
Attacker Value
Unknown

CVE-2019-11095

Disclosure Date: May 17, 2019 (last updated November 27, 2024)
Insufficient access control in Intel(R) Driver & Support Assistant version 19.3.12.3 and before may allow a privileged user to potentially enable information disclosure via local access.
0
Attacker Value
Unknown

CVE-2019-11114

Disclosure Date: May 17, 2019 (last updated November 27, 2024)
Insufficient input validation in Intel(R) Driver & Support Assistant version 19.3.12.3 and before may allow a privileged user to potentially enable denial of service via local access.
0
Attacker Value
Unknown

CVE-2019-3719

Disclosure Date: April 18, 2019 (last updated December 06, 2023)
Dell SupportAssist Client versions prior to 3.2.0.90 contain a remote code execution vulnerability. An unauthenticated attacker, sharing the network access layer with the vulnerable system, can compromise the vulnerable system by tricking a victim user into downloading and executing arbitrary executables via SupportAssist client from attacker hosted sites.
Attacker Value
Unknown

CVE-2019-3718

Disclosure Date: April 18, 2019 (last updated November 27, 2024)
Dell SupportAssist Client versions prior to 3.2.0.90 contain an improper origin validation vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to attempt CSRF attacks on users of the impacted systems.
Attacker Value
Unknown

CVE-2019-11223

Disclosure Date: April 18, 2019 (last updated November 27, 2024)
An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension.
0