Latest CVE Feed
-
5.5
MEDIUMCVE-2019-5239
Huawei PCManager with the versions before 9.0.1.66 (Oversea) and versions before 9.0.1.70 (China) have an information leak vulnerability. Successful exploitation may cause the attacker to read information.... Read more
- EPSS Score: %0.11
- Published: Aug. 08, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-5230
P20 Pro, P20, Mate RS smartphones with versions earlier than Charlotte-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier than Emily-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier than NEO-AL00D NEO-AL00 9.1.0.321(C786E320R1P1T8) have an improper validati... Read more
- EPSS Score: %0.12
- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-5224
P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21) have an out of bounds read vulnerability. The system does not properly validate certain length parameter which an application transports to kernel. An attacker tricks the user t... Read more
- EPSS Score: %0.14
- Published: Nov. 29, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-5222
There is an information disclosure vulnerability on Secure Input of certain Huawei smartphones in Versions earlier than Tony-AL00B 9.1.0.216(C00E214R2P1). The Secure Input does not properly limit certain system privilege. An attacker tricks the user to in... Read more
- EPSS Score: %0.09
- Published: Jul. 17, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-5256
Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have a null pointer dereference vul... Read more
- EPSS Score: %0.06
- Published: Dec. 13, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-5258
Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have a buffer overflow vulnerabilit... Read more
- EPSS Score: %0.07
- Published: Dec. 13, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-5182
An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send a specially crafted packet to trigger the parsing of this cache f... Read more
- EPSS Score: %0.07
- Published: Mar. 11, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-5176
An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send a specially crafted packet to trigger the parsing of this cache f... Read more
- EPSS Score: %0.07
- Published: Mar. 12, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-5106
A hard-coded encryption key vulnerability exists in the authentication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to communications between e!Cockpit and CoDeSyS Gateway can trivially recover the password of any user attempti... Read more
Affected Products : e\!cockpit- EPSS Score: %0.06
- Published: Mar. 11, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-5005
An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. They allowed Denial of Service (application crash) via image data, because two bytes are written to the end of the allocated memory without judging whether this will cause corru... Read more
- EPSS Score: %0.08
- Published: Jan. 03, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-4731
IBM MQ Appliance 9.1.4.CD could allow a local attacker to obtain highly sensitive information by inclusion of sensitive data within trace. IBM X-Force ID: 172616.... Read more
Affected Products : mq_appliance- EPSS Score: %0.04
- Published: Jul. 28, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-4719
IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive information by inclusion of sensitive data within runmqras data.... Read more
- EPSS Score: %0.09
- Published: Mar. 16, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-4619
IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive information by inclusion of sensitive data within trace. IBM X-Force ID: 168862.... Read more
- EPSS Score: %0.09
- Published: Mar. 16, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-4446
IBM Maximo Asset Management 7.6 could allow an authenticated user perform actions they are not authorized to by modifying request parameters. IBM X-Force ID: 163490.... Read more
- EPSS Score: %0.12
- Published: Apr. 17, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-4444
IBM API Connect 2018.1 through 2018.4.1.7 Developer Portal's user registration page does not disable password autocomplete. An attacker with access to the browser instance and local system credentials can steal the credentials used for registration. IBM X... Read more
Affected Products : api_connect- EPSS Score: %0.10
- Published: Dec. 16, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-4307
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 160987.... Read more
Affected Products : security_guardium_big_data_intelligence- EPSS Score: %0.10
- Published: Oct. 29, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-4299
IBM Robotic Process Automation with Automation Anywhere 11 could allow a local user to obtain highly sensitive information from log files when debugging is enabled. IBM X-Force ID: 160765.... Read more
Affected Products : robotic_process_automation_with_automation_anywhere- EPSS Score: %0.10
- Published: Jul. 01, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-4259
A security vulnerability has been identified in IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 with CES stack enabled that could allow sensitive data to be included with service snaps. IBM X-Force ID: 160011.... Read more
Affected Products : spectrum_scale- EPSS Score: %0.04
- Published: May. 13, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-4158
IBM Security Access Manager 9.0.1 through 9.0.6 does not prove that a user's identity is correct which can lead to the exposure of resources or functionality to unintended actors. IBM X-Force ID: 158574.... Read more
Affected Products : security_access_manager- EPSS Score: %0.09
- Published: Jun. 25, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-3970
Comodo Antivirus versions up to 12.0.0.6810 are vulnerable to Arbitrary File Write due to Cavwp.exe handling of Comodo's Antivirus database. Cavwp.exe loads Comodo antivirus definition database in unsecured global section objects, allowing a local low pri... Read more
Affected Products : antivirus- EPSS Score: %0.05
- Published: Jul. 17, 2019
- Modified: Nov. 21, 2024