National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

Search Results (Refine Search)

There are 130,965 matching records.
Displaying matches 41 through 60.
Vuln ID Summary CVSS Severity
CVE-2019-19879

HashiCorp Sentinel up to 0.10.1 incorrectly parsed negation in certain policy expressions. Fixed in 0.10.2.

Published: February 14, 2020; 12:15:12 PM -05:00
(not available)
CVE-2019-19758

A vulnerability in the web interface of Lenovo EZ Media & Backup Center, ix2 & ix2-dl version 4.1.406.34763 and prior could allow an unauthenticated, remote attacker to redirect a user to an untrusted web page.

Published: February 14, 2020; 12:15:11 PM -05:00
(not available)
CVE-2019-19757

An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) based cross-site scripting vulnerability in versions prior to 2.6.6 that could allow JavaScript code to be executed in the user's web browser if a specially crafted link is visited. The JavaScript code is executed on the user's system, not executed on LXCA itself.

Published: February 14, 2020; 12:15:11 PM -05:00
(not available)
CVE-2019-20455

Gateways/Gateway.php in Heartland & Global Payments PHP SDK before 2.0.0 does not enforce SSL certificate validations.

Published: February 14, 2020; 11:15:09 AM -05:00
(not available)
CVE-2018-21033

A vulnerability in Hitachi Command Suite prior to 8.6.2-00, Hitachi Automation Director prior to 8.6.2-00 and Hitachi Infrastructure Analytics Advisor prior to 4.2.0-00 allow authenticated remote users to load an arbitrary Cascading Style Sheets (CSS) token sequence. Hitachi Command Suite includes Hitachi Device Manager, Hitachi Tiered Storage Manager, Hitachi Replication Manager, Hitachi Tuning Manager, Hitachi Global Link Manager and Hitachi Compute Systems Manager.

Published: February 14, 2020; 11:15:09 AM -05:00
(not available)
CVE-2018-21032

A vulnerability in Hitachi Command Suite prior to 8.7.1-00 and Hitachi Automation Director prior to 8.5.0-00 allow authenticated remote users to expose technical information through error messages. Hitachi Command Suite includes Hitachi Device Manager and Hitachi Compute Systems Manager.

Published: February 14, 2020; 11:15:09 AM -05:00
(not available)
CVE-2020-7251

Improper access control vulnerability in Configuration Tool in McAfee Mcafee Endpoint Security (ENS) Prior to 10.6.1 February 2020 Update allows local users to disable security features via unauthorised use of the configuration tool from older versions of ENS.

Published: February 14, 2020; 10:15:11 AM -05:00
(not available)
CVE-2020-5532

ilbo App (ilbo App for Android prior to version 1.1.8 and ilbo App for iOS prior to version 1.2.01) allows an attacker on the same network segment to bypass authentication and to view the images which were recorded by the other ilbo user's device via unspecified vectors.

Published: February 14, 2020; 09:15:10 AM -05:00
(not available)
CVE-2019-20454

An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF mode. Applications that use PCRE to parse untrusted input may be vulnerable to this flaw, which would allow an attacker to crash the application. The flaw occurs in do_extuni_no_utf in pcre2_jit_compile.c.

Published: February 14, 2020; 09:15:10 AM -05:00
(not available)
CVE-2020-8992

ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a denial of service (soft lockup) via a crafted journal size.

Published: February 14, 2020; 12:15:13 AM -05:00
(not available)
CVE-2020-8991

vg_lookup in daemons/lvmetad/lvmetad-core.c in LVM2 2.02 mismanages memory, leading to an lvmetad memory leak, as demonstrated by running pvs.

Published: February 14, 2020; 12:15:13 AM -05:00
(not available)
CVE-2013-5687

RiskNet Acquirer before hotfix 6.0 b7+ADHOC-443 ApplicationServiceBean contains a service information disclosure.

Published: February 13, 2020; 07:15:11 PM -05:00
(not available)
CVE-2013-5212

Cross-site Scripting (XSS) in EasyXDM before 2.4.18 allows remote attackers to inject arbitrary web script or html via the easyxdm.swf file.

Published: February 13, 2020; 07:15:10 PM -05:00
(not available)
CVE-2013-4792

PrestaShop before 1.4.11 allows logout CSRF.

Published: February 13, 2020; 07:15:10 PM -05:00
(not available)
CVE-2013-4791

PrestaShop before 1.4.11 allows Logistician, translators and other low level profiles/accounts to inject a persistent XSS vector on TinyMCE.

Published: February 13, 2020; 07:15:10 PM -05:00
(not available)
CVE-2013-7287

MobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme.

Published: February 13, 2020; 06:15:12 PM -05:00
(not available)
CVE-2013-7173

Belkin n750 routers have a buffer overflow.

Published: February 13, 2020; 06:15:11 PM -05:00
(not available)
CVE-2013-7098

OpenConnect VPN client with GnuTLS before 5.02 contains a heap overflow if MTU is increased on reconnection.

Published: February 13, 2020; 06:15:11 PM -05:00
(not available)
CVE-2013-6927

Internet TRiLOGI Server (unknown versions) could allow a local user to bypass security and create a local user account.

Published: February 13, 2020; 06:15:11 PM -05:00
(not available)
CVE-2013-6362

Xerox ColorCube and WorkCenter devices in 2013 had hardcoded FTP and shell user accounts.

Published: February 13, 2020; 06:15:11 PM -05:00
(not available)