Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
Total 32127 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-6330 1 Hp 1 Access Control 2024-11-21 7.5 HIGH 9.8 CRITICAL
A potential security vulnerability has been identified in the software solution HP Access Control versions prior to 16.7. This vulnerability could potentially grant elevation of privilege.
CVE-2019-6329 1 Hp 1 Support Assistant 2024-11-21 7.2 HIGH 7.8 HIGH
HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of directories or files. Note: A different vulnerability than CVE-2019-6328.
CVE-2019-6328 1 Hp 1 Support Assistant 2024-11-21 7.2 HIGH 7.8 HIGH
HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of directories or files. Note: A different vulnerability than CVE-2019-6329.
CVE-2019-6279 1 Chinamobileltd 2 Gpn2.4p21-c-cn, Gpn2.4p21-c-cn Firmware 2024-11-21 6.8 MEDIUM 8.8 HIGH
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have an Incorrect Access Control vulnerability via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security Password.
CVE-2019-6265 1 Cordaware 1 Bestinformed 2024-11-21 4.6 MEDIUM 7.8 HIGH
The Scripting and AutoUpdate functionality in Cordaware bestinformed Microsoft Windows client versions before 6.2.1.0 are affected by insecure implementations which allow remote attackers to execute arbitrary commands and escalate privileges.
CVE-2019-6260 2 Aspeedtech, Netapp 5 Ast2400, Ast2400 Firmware, Ast2500 and 2 more 2024-11-21 7.5 HIGH 9.8 CRITICAL
The ASPEED ast2400 and ast2500 Baseband Management Controller (BMC) hardware and firmware implement Advanced High-performance Bus (AHB) bridges, which allow arbitrary read and write access to the BMC's physical address space from the host (or from the network in unusual cases where the BMC console uart is attached to a serial concentrator). This CVE applies to the specific cases of iLPC2AHB bridge Pt I, iLPC2AHB bridge Pt II, PCIe VGA P2A bridge, DMA from/to arbitrary BMC memory via X-DMA, UART-based SoC Debug interface, LPC2AHB bridge, PCIe BMC P2A bridge, and Watchdog setup.
CVE-2019-6251 6 Canonical, Fedoraproject, Gnome and 3 more 6 Ubuntu Linux, Fedora, Epiphany and 3 more 2024-11-21 5.8 MEDIUM 8.1 HIGH
WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.
CVE-2019-6241 1 Bevywise 1 Mqttroute 2024-11-21 5.0 MEDIUM 7.5 HIGH
In Bevywise MQTTRoute 1.1 build 1018-002, a connect packet combined with a malformed unsubscribe request packet can be used to cause a Denial of Service attack against the broker.
CVE-2019-6239 1 Apple 1 Mac Os X 2024-11-21 4.6 MEDIUM 7.8 HIGH
This issue was addressed with improved handling of file metadata. This issue is fixed in macOS Mojave 10.14.4. A malicious application may bypass Gatekeeper checks.
CVE-2019-6222 1 Apple 1 Iphone Os 2024-11-21 4.3 MEDIUM 4.3 MEDIUM
A consistency issue was addressed with improved state handling. This issue is fixed in iOS 12.2. A website may be able to access the microphone without the microphone use indicator being shown.
CVE-2019-6203 1 Apple 3 Iphone Os, Mac Os X, Tvos 2024-11-21 7.5 HIGH 9.8 CRITICAL
A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2. An attacker in a privileged network position may be able to intercept network traffic.
CVE-2019-6191 1 Lenovo 1 Paper 2024-11-21 4.6 MEDIUM 7.8 HIGH
A potential vulnerability in the discontinued LenovoPaper software version 1.0.0.22 may allow local privilege escalation.
CVE-2019-6188 1 Lenovo 784 130-14ikb, 130-14ikb Firmware, 130-15ikb and 781 more 2024-11-21 7.5 HIGH 9.8 CRITICAL
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access.
CVE-2019-6186 1 Lenovo 1 System Interface Foundation 2024-11-21 6.5 MEDIUM 8.8 HIGH
A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow an authenticated user to execute code as another user.
CVE-2019-6184 1 Lenovo 1 Customer Engagement Service 2024-11-21 4.6 MEDIUM 7.8 HIGH
A potential vulnerability in the discontinued Customer Engagement Service (CCSDK) software version 2.0.21.1 may allow local privilege escalation.
CVE-2019-6183 1 Lenovo 1 Energy Management 2024-11-21 7.8 HIGH 7.5 HIGH
A denial of service vulnerability has been reported in Lenovo Energy Management Driver for Windows 10 versions prior to 15.11.29.7 that could cause systems to experience a blue screen error. Lenovo Energy Management is a client utility. Lenovo XClarity Energy Manager is not affected.
CVE-2019-6178 1 Lenovo 12 Home Media Network Hard Drive, Home Media Network Hard Drive Firmware, Ix12-300r and 9 more 2024-11-21 4.3 MEDIUM 5.3 MEDIUM
An information leakage vulnerability in Iomega and LenovoEMC NAS products could allow disclosure of some device details such as Share names through the device API when Personal Cloud is enabled. This does not allow read, write, delete, or any other access to the underlying file systems and their contents.
CVE-2019-6176 1 Lenovo 2 Thinkpad Usb-c Dock, Thinkpad Usb-c Dock Firmware 2024-11-21 5.0 MEDIUM 7.5 HIGH
A potential vulnerability reported in ThinkPad USB-C Dock Firmware version 3.7.2 may allow a denial of service.
CVE-2019-6175 1 Lenovo 1 System Update 2024-11-21 7.8 HIGH 7.5 HIGH
A denial of service vulnerability was reported in Lenovo System Update versions prior to 5.07.0088 that could allow configuration files to be written to non-standard locations.
CVE-2019-6172 1 Lenovo 784 130-14ikb, 130-14ikb Firmware, 130-15ikb and 781 more 2024-11-21 4.4 MEDIUM 6.4 MEDIUM
A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution.