NVD: fully analised CVE

Subscribe to NVD: fully analised CVE hírcsatorna
This feed contains the most recent CVE cyber vulnerabilities published within the National Vulnerability Database.
Frissítve: 1 óra 40 perc
2019. november 14.

CVE-2012-1170 (fedora, moodle)

Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough
2019. november 14.

CVE-2012-1159 (fedora, moodle)

Moodle before 2.2.2: Overview report allows users to see hidden courses
2019. november 14.

CVE-2012-1161 (fedora, moodle)

Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results
2019. november 14.

CVE-2019-18646 (ng_firewall)

The Untangle NG firewall 14.2.0 is vulnerable to authenticated inline-query SQL injection within the timeDataDynamicColumn parameter when logged in as an admin user.
2019. november 14.

CVE-2019-18647 (ng_firewall)

The Untangle NG firewall 14.2.0 is vulnerable to an authenticated command injection when logged in as an admin user.
2019. november 14.

CVE-2019-18648 (ng_firewall)

When logged in as an admin user, the Untangle NG firewall 14.2.0 is vulnerable to reflected XSS at multiple places and specific user input fields.
2019. november 14.

CVE-2019-18649 (ng_firewall)

When logged in as an admin user, the Title input field (under Reports) within Untangle NG firewall 14.2.0 is vulnerable to stored XSS.
2019. november 14.

CVE-2019-18957 (microstrategy_library)

Microstrategy Library in MicroStrategy before 2019 before 11.1.3 has reflected XSS.
2019. november 14.

CVE-2019-3661 (advanced_threat_defense)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to execute database commands via carefully constructed time based payloads.
2019. november 14.

CVE-2019-3662 (advanced_threat_defense)

Path Traversal: '/absolute/pathname/here' vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to gain unintended access to files on the system via carefully constructed HTTP requests.
2019. november 14.

CVE-2019-3663 (advanced_threat_defense)

Unprotected Storage of Credentials vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows local attacker to gain access to the root password via accessing sensitive files on the system.
2019. november 14.

CVE-2011-0544 (debian_linux, phpbb)

phpbb 3.0.x-3.0.6 has an XSS vulnerability via the [flash] BB tag.
2019. november 14.

CVE-2019-3660 (advanced_threat_defense)

Improper Neutralization of HTTP requests in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to execute commands on the server remotely via carefully constructed HTTP requests.
2019. november 14.

CVE-2019-0396 (businessobjects_business_intelligence_platform)

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can craft a message that contains malicious elements that will not be correctly filtered by Web Intelligence HTML interface in some specific workflows.
2019. november 14.

CVE-2019-18951 (xfilesharing)

SibSoft Xfilesharing through 2.5.1 allows op=page&tmpl=../ directory traversal to read arbitrary files.
2019. november 14.

CVE-2019-18952 (xfilesharing)

SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code execution via a .html file, containing short codes, that is served over HTTP.
2019. november 14.

CVE-2019-3649 (advanced_threat_defense)

Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attackers to gain access to hashed credentials via carefully constructed POST request extracting incorrectly recorded data from log files.
2019. november 14.

CVE-2019-3650 (advanced_threat_defense)

Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated attackers to gain access to the atduser credentials via carefully constructed GET request extracting insecurely information stored in the database.
2019. november 14.

CVE-2019-3651 (advanced_threat_defense)

Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated attackers to gain access to ePO as an administrator via using the atduser credentials, which were too permissive.
2019. november 13.

CVE-2019-0382 (businessobjects_business_intelligence_platform)

A Cross-Site Scripting vulnerability exists in SAP BusinessObjects Business Intelligence Platform (Web Intelligence-Publication related pages); corrected in version 4.2. Privileges are required in order to exploit this vulnerability.