Show filters
817 Total Results
Displaying 641-650 of 817
Sort by:
Attacker Value
Unknown
Openfind MAIL2000 Webmail Pre-Auth Cross-Site Scripting
Disclosure Date: November 20, 2019 (last updated November 27, 2024)
The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via ACTION parameter without authentication. The code can executed for any user accessing the page. This vulnerability affects many mail system of governments, organizations, companies and universities.
0
Attacker Value
Unknown
CVE-2019-15334
Disclosure Date: November 14, 2019 (last updated November 27, 2024)
The Lava Iris 88 Go Android device with a build fingerprint of LAVA/iris88_go/iris88_go:8.1.0/O11019/1538188945:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.
0
Attacker Value
Unknown
CVE-2019-15362
Disclosure Date: November 14, 2019 (last updated November 27, 2024)
The Lava Iris 88 Go Android device with a build fingerprint of LAVA/iris88_go/iris88_go:8.1.0/O11019/1538188945:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
0
Attacker Value
Unknown
CVE-2019-18923
Disclosure Date: November 13, 2019 (last updated November 27, 2024)
Insufficient content type validation of proxied resources in go-camo before 2.1.1 allows a remote attacker to serve arbitrary content from go-camo's origin.
0
Attacker Value
Unknown
CVE-2019-0210
Disclosure Date: October 29, 2019 (last updated November 08, 2023)
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.
0
Attacker Value
Unknown
CVE-2019-17596
Disclosure Date: October 24, 2019 (last updated November 08, 2023)
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.
0
Attacker Value
Unknown
CVE-2019-15265
Disclosure Date: October 16, 2019 (last updated November 27, 2024)
A vulnerability in the bridge protocol data unit (BPDU) forwarding functionality of Cisco Aironet Access Points (APs) could allow an unauthenticated, adjacent attacker to cause an AP port to go into an error disabled state. The vulnerability occurs because BPDUs received from specific wireless clients are forwarded incorrectly. An attacker could exploit this vulnerability on the wireless network by sending a steady stream of crafted BPDU frames. A successful exploit could allow the attacker to cause a limited denial of service (DoS) attack because an AP port could go offline.
0
Attacker Value
Unknown
CVE-2019-16276
Disclosure Date: September 30, 2019 (last updated November 08, 2023)
Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.
0
Attacker Value
Unknown
CVE-2019-16319
Disclosure Date: September 15, 2019 (last updated November 08, 2023)
In Wireshark 3.0.0 to 3.0.3 and 2.6.0 to 2.6.10, the Gryphon dissector could go into an infinite loop. This was addressed in plugins/epan/gryphon/packet-gryphon.c by checking for a message length of zero.
0
Attacker Value
Unknown
Kubernetes kubelet exposes /debug/pprof info on healthz port
Disclosure Date: August 29, 2019 (last updated November 27, 2024)
The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is exposed over the Kubelet's healthz port. This debugging endpoint can potentially leak sensitive information such as internal Kubelet memory addresses and configuration, or for limited denial of service. Versions prior to 1.15.0, 1.14.4, 1.13.8, and 1.12.10 are affected. The issue is of medium severity, but not exposed by the default configuration.
0