Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In 2019
A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page.
CVSS Score
6.5
EPSS Score
0.001
Published
2019-12-20
An insecure file access vulnerability exists in CA Client Automation 14.0, 14.1, 14.2, and 14.3 Agent for Windows that can allow a local attacker to gain escalated privileges.
CVSS Score
7.3
EPSS Score
0.002
Published
2019-12-20
Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c.
CVSS Score
7.8
EPSS Score
0.004
Published
2019-12-20
Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c.
CVSS Score
7.8
EPSS Score
0.004
Published
2019-12-20
NeuVector 3.1 when configured to allow authentication via Active Directory, does not enforce non-empty passwords which allows an attacker with access to the Neuvector portal to authenticate as any valid LDAP user by providing a valid username and an empty password (provided that the active directory server has not been configured to reject empty passwords).
CVSS Score
9.8
EPSS Score
0.005
Published
2019-12-20
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 159356.
CVSS Score
4.3
EPSS Score
0.002
Published
2019-12-20
IBM Cognos Analytics 11.0 and 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 166204.
CVSS Score
5.4
EPSS Score
0.003
Published
2019-12-20
IBM Financial Transaction Manager 3.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 172706.
CVSS Score
4.3
EPSS Score
0.001
Published
2019-12-20
IBM Financial Transaction Manager 3.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 172877.
CVSS Score
6.1
EPSS Score
0.002
Published
2019-12-20
IBM Financial Transaction Manager 3.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 172880.
CVSS Score
4.3
EPSS Score
0.001
Published
2019-12-20


Contact Us

Shodan ® - All rights reserved