Search

Search Results (356023 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-7291 1 Apple 1 Airport Base Station Firmware 2024-11-21 6.5 Medium
A denial of service issue was addressed with improved memory handling. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. An attacker in a privileged position may be able to perform a denial of service attack.
CVE-2019-7290 1 Apple 1 Shortcuts 2024-11-21 10.0 Critical
An access issue was addressed with additional sandbox restrictions. This issue is fixed in Shortcuts 2.1.3 for iOS. A sandboxed process may be able to circumvent sandbox restrictions.
CVE-2019-7289 1 Apple 1 Shortcuts 2024-11-21 5.5 Medium
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in Shortcuts 2.1.3 for iOS. A local user may be able to view senstive user information.
CVE-2019-7288 1 Apple 2 Iphone Os, Mac Os X 2024-11-21 9.8 Critical
The issue was addressed with improved validation on the FaceTime server. This issue is fixed in macOS Mojave 10.14.3 Supplemental Update, iOS 12.1.4. A thorough security audit of the FaceTime service uncovered an issue with Live Photos .
CVE-2019-7285 2 Apple, Redhat 6 Icloud, Iphone Os, Itunes and 3 more 2024-11-21 8.8 High
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.
CVE-2019-7284 1 Apple 1 Iphone Os 2024-11-21 4.3 Medium
This issue was addressed with improved checks. This issue is fixed in iOS 12.2. Processing a maliciously crafted mail message may lead to S/MIME signature spoofing.
CVE-2019-7283 2 Debian, Netkit 2 Debian Linux, Netkit 2024-11-21 7.4 High
An issue was discovered in rcp in NetKit through 0.17. For an rcp operation, the server chooses which files/directories are sent to the client. However, the rcp client only performs cursory validation of the object name returned. A malicious rsh server (or Man-in-The-Middle attacker) can overwrite arbitrary files in a directory on the rcp client machine. This is similar to CVE-2019-6111.
CVE-2019-7282 3 Debian, Fedoraproject, Netkit 3 Debian Linux, Fedora, Netkit 2024-11-21 5.9 Medium
In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.
CVE-2019-7281 1 Primasystems 1 Flexair 2024-11-21 8.8 High
Prima Systems FlexAir, Versions 2.3.38 and prior. An unauthenticated user can send unverified HTTP requests, which may allow the attacker to perform certain actions with administrative privileges if a logged-in user visits a malicious website.
CVE-2019-7280 1 Primasystems 1 Flexair 2024-11-21 8.8 High
Prima Systems FlexAir, Versions 2.3.38 and prior. The session-ID is of an insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session and bypass authentication.
CVE-2019-7279 1 Optergy 2 Enterprise, Proton 2024-11-21 N/A
Optergy Proton/Enterprise devices have Hard-coded Credentials.
CVE-2019-7278 1 Optergy 2 Enterprise, Proton 2024-11-21 N/A
Optergy Proton/Enterprise devices have an Unauthenticated SMS Sending Service.
CVE-2019-7277 1 Optergy 2 Enterprise, Proton 2024-11-21 N/A
Optergy Proton/Enterprise devices allow Unauthenticated Internal Network Information Disclosure.
CVE-2019-7276 1 Optergy 2 Enterprise, Proton 2024-11-21 N/A
Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.
CVE-2019-7275 1 Optergy 2 Enterprise, Proton 2024-11-21 6.1 Medium
Optergy Proton/Enterprise devices allow Open Redirect.
CVE-2019-7274 1 Optergy 2 Enterprise, Proton 2024-11-21 9.8 Critical
Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root.
CVE-2019-7273 1 Optergy 2 Enterprise, Proton 2024-11-21 8.8 High
Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF).
CVE-2019-7272 1 Optergy 2 Enterprise, Proton 2024-11-21 5.3 Medium
Optergy Proton/Enterprise devices allow Username Disclosure.
CVE-2019-7271 1 Nortekcontrol 4 Linear Emerge 5000p, Linear Emerge 5000p Firmware, Linear Emerge 50p and 1 more 2024-11-21 N/A
Nortek Linear eMerge 50P/5000P devices have Default Credentials.
CVE-2019-7270 1 Nortekcontrol 4 Linear Emerge 5000p, Linear Emerge 5000p Firmware, Linear Emerge 50p and 1 more 2024-11-21 8.8 High
Linear eMerge 50P/5000P devices allow Cross-Site Request Forgery (CSRF).