Network Information
+
IPv4:
- 165.22.65.139
+
IPv6:
- 2a03:b0c0:3:e0::27e:2001
+
Location:
Country:
DE
Country Code:
DE
Region:
Hesse
Region Code:
Not Available
City:
Frankfurt am Main
Postal Code:
60311
Latitude:
50.1155
Longitude:
8.6842
Timezone:
Europe/Berlin
+
NS Records:
- dns1.registrar-servers.com
- dns2.registrar-servers.com
+
Text Records:
-
Not Available
+
SOA Records:
Not Available
+
MX Records:
-
Not Available
Analysis Results
+
Netlify
+
CVE-2019-7551
Date: 06-02-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7551
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-7551
🔗
Status: Candidate
Description: Cantemo Portal before 3.2.13, 3.3.x before 3.3.8, and 3.4.x before 3.4.9 has XSS. Leveraging this vulnerability would enable performing actions as users, including administrative users. This could enable account creation and deletion as well as deletion of information contained within the app.
+
Gatsby
(v2.3.3)
+
Google Analytics
+
CVE-2019-11617
Date: 30-04-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11617
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-11617
🔗
Status: Candidate
Description: doorGets 7.0 has a CSRF vulnerability in /doorgets/app/requests/user/configurationRequest.php. A remote attacker can exploit this vulnerability for "Google Analytics code" modification.
+
Google Font API
+
Google Tag Manager
+
Netlify
+
CVE-2019-7551
Date: 06-02-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7551
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-7551
🔗
Status: Candidate
Description: Cantemo Portal before 3.2.13, 3.3.x before 3.3.8, and 3.4.x before 3.4.9 has XSS. Leveraging this vulnerability would enable performing actions as users, including administrative users. This could enable account creation and deletion as well as deletion of information contained within the app.
+
webpack
+
React
+
CVE-2019-11284
Date: 18-04-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11284
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-11284
🔗
Status: Candidate
Description: Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to.
+
CVE-2019-12153
Date: 17-05-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12153
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-12153
🔗
Status: Candidate
Description: Lack of validation in the HTML parser in RealObjects PDFreactor before 10.1.10722 leads to SSRF, allowing attackers to access network or file resources on behalf of the server by supplying malicious HTML content.
+
CVE-2019-12154
Date: 17-05-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12154
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-12154
🔗
Status: Candidate
Description: XXE in the XML parser library in RealObjects PDFreactor before 10.1.10722 allows attackers to supply malicious XML content in externally referenced resources, leading to disclosure of local file contents and/or denial of service conditions.
+
CVE-2019-12164
Date: 17-05-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12164
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-12164
🔗
Status: Candidate
Description: ubuntu-server.js in Status React Native Desktop before v0.57.8_mobile_ui allows Remote Code Execution.
+
CVE-2019-13347
Date: 05-07-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13347
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-13347
🔗
Status: Candidate
Description: An issue was discovered in the SAML Single Sign On (SSO) plugin for several Atlassian products affecting versions 3.1.0 through 3.2.2 for Jira and Confluence, versions 2.4.0 through 3.0.3 for Bitbucket, and versions 2.4.0 through 2.5.2 for Bamboo. It allows locally disabled users to reactivate their accounts just by browsing the affected Jira/Confluence/Bitbucket/Bamboo instance, even when the applicable configuration option of the plugin has been disabled ("Reactivate inactive users"). Exploiting this vulnerability requires an attacker to be authorized by the identity provider and requires that the plugin's configuration option "User Update Method" have the "Update from SAML Attributes" value.
+
CVE-2019-14261
Date: 25-07-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14261
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-14261
🔗
Status: Candidate
Description: An issue was discovered on ABUS Secvest FUAA50000 3.01.01 devices. Due to an insufficient implementation of jamming detection, an attacker is able to suppress correctly received RF messages sent between wireless peripheral components, e.g., wireless detectors or remote controls, and the ABUS Secvest alarm central. An attacker is able to perform a "reactive jamming" attack. The reactive jamming simply detects the start of a RF message sent by a component of the ABUS Secvest wireless alarm system, for instance a wireless motion detector (FUBW50000) or a remote control (FUBE50014 or FUBE50015), and overlays it with random data before the original RF message ends. Thereby, the receiver (alarm central) is not able to properly decode the original transmitted signal. This enables an attacker to suppress correctly received RF messages of the wireless alarm system in an unauthorized manner, for instance status messages sent by a detector indicating an intrusion.
+
CVE-2019-16770
Date: 24-09-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16770
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-16770
🔗
Status: Candidate
Description: In Puma before version 4.3.2, a poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack. If more keepalive connections to Puma are opened than there are threads available, additional connections will wait permanently if the attacker sends requests frequently enough.
+
CVE-2019-7176
Date: 29-01-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7176
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-7176
🔗
Status: Candidate
Description: An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2. It has Incorrect Access Control. Guest users are able to add reaction emojis on comments to which they have no visibility.
+
Gatsby
(v2.3.3)
+
Google Analytics
+
CVE-2019-11617
Date: 30-04-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11617
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-11617
🔗
Status: Candidate
Description: doorGets 7.0 has a CSRF vulnerability in /doorgets/app/requests/user/configurationRequest.php. A remote attacker can exploit this vulnerability for "Google Analytics code" modification.
+
Google Font API
+
Google Tag Manager
+
Netlify
+
CVE-2019-7551
Date: 06-02-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7551
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-7551
🔗
Status: Candidate
Description: Cantemo Portal before 3.2.13, 3.3.x before 3.3.8, and 3.4.x before 3.4.9 has XSS. Leveraging this vulnerability would enable performing actions as users, including administrative users. This could enable account creation and deletion as well as deletion of information contained within the app.
+
webpack
+
React
+
CVE-2019-11284
Date: 18-04-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11284
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-11284
🔗
Status: Candidate
Description: Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to.
+
CVE-2019-12153
Date: 17-05-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12153
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-12153
🔗
Status: Candidate
Description: Lack of validation in the HTML parser in RealObjects PDFreactor before 10.1.10722 leads to SSRF, allowing attackers to access network or file resources on behalf of the server by supplying malicious HTML content.
+
CVE-2019-12154
Date: 17-05-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12154
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-12154
🔗
Status: Candidate
Description: XXE in the XML parser library in RealObjects PDFreactor before 10.1.10722 allows attackers to supply malicious XML content in externally referenced resources, leading to disclosure of local file contents and/or denial of service conditions.
+
CVE-2019-12164
Date: 17-05-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12164
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-12164
🔗
Status: Candidate
Description: ubuntu-server.js in Status React Native Desktop before v0.57.8_mobile_ui allows Remote Code Execution.
+
CVE-2019-13347
Date: 05-07-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13347
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-13347
🔗
Status: Candidate
Description: An issue was discovered in the SAML Single Sign On (SSO) plugin for several Atlassian products affecting versions 3.1.0 through 3.2.2 for Jira and Confluence, versions 2.4.0 through 3.0.3 for Bitbucket, and versions 2.4.0 through 2.5.2 for Bamboo. It allows locally disabled users to reactivate their accounts just by browsing the affected Jira/Confluence/Bitbucket/Bamboo instance, even when the applicable configuration option of the plugin has been disabled ("Reactivate inactive users"). Exploiting this vulnerability requires an attacker to be authorized by the identity provider and requires that the plugin's configuration option "User Update Method" have the "Update from SAML Attributes" value.
+
CVE-2019-14261
Date: 25-07-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14261
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-14261
🔗
Status: Candidate
Description: An issue was discovered on ABUS Secvest FUAA50000 3.01.01 devices. Due to an insufficient implementation of jamming detection, an attacker is able to suppress correctly received RF messages sent between wireless peripheral components, e.g., wireless detectors or remote controls, and the ABUS Secvest alarm central. An attacker is able to perform a "reactive jamming" attack. The reactive jamming simply detects the start of a RF message sent by a component of the ABUS Secvest wireless alarm system, for instance a wireless motion detector (FUBW50000) or a remote control (FUBE50014 or FUBE50015), and overlays it with random data before the original RF message ends. Thereby, the receiver (alarm central) is not able to properly decode the original transmitted signal. This enables an attacker to suppress correctly received RF messages of the wireless alarm system in an unauthorized manner, for instance status messages sent by a detector indicating an intrusion.
+
CVE-2019-16770
Date: 24-09-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16770
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-16770
🔗
Status: Candidate
Description: In Puma before version 4.3.2, a poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack. If more keepalive connections to Puma are opened than there are threads available, additional connections will wait permanently if the attacker sends requests frequently enough.
+
CVE-2019-7176
Date: 29-01-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7176
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-7176
🔗
Status: Candidate
Description: An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2. It has Incorrect Access Control. Guest users are able to add reaction emojis on comments to which they have no visibility.
+
Gatsby
(v2.3.3)
+
Google Analytics
+
CVE-2019-11617
Date: 30-04-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11617
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-11617
🔗
Status: Candidate
Description: doorGets 7.0 has a CSRF vulnerability in /doorgets/app/requests/user/configurationRequest.php. A remote attacker can exploit this vulnerability for "Google Analytics code" modification.
+
Google Font API
+
Google Tag Manager
+
Netlify
+
CVE-2019-7551
Date: 06-02-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7551
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-7551
🔗
Status: Candidate
Description: Cantemo Portal before 3.2.13, 3.3.x before 3.3.8, and 3.4.x before 3.4.9 has XSS. Leveraging this vulnerability would enable performing actions as users, including administrative users. This could enable account creation and deletion as well as deletion of information contained within the app.
+
webpack
+
React
+
CVE-2019-11284
Date: 18-04-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11284
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-11284
🔗
Status: Candidate
Description: Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to.
+
CVE-2019-12153
Date: 17-05-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12153
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-12153
🔗
Status: Candidate
Description: Lack of validation in the HTML parser in RealObjects PDFreactor before 10.1.10722 leads to SSRF, allowing attackers to access network or file resources on behalf of the server by supplying malicious HTML content.
+
CVE-2019-12154
Date: 17-05-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12154
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-12154
🔗
Status: Candidate
Description: XXE in the XML parser library in RealObjects PDFreactor before 10.1.10722 allows attackers to supply malicious XML content in externally referenced resources, leading to disclosure of local file contents and/or denial of service conditions.
+
CVE-2019-12164
Date: 17-05-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12164
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-12164
🔗
Status: Candidate
Description: ubuntu-server.js in Status React Native Desktop before v0.57.8_mobile_ui allows Remote Code Execution.
+
CVE-2019-13347
Date: 05-07-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13347
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-13347
🔗
Status: Candidate
Description: An issue was discovered in the SAML Single Sign On (SSO) plugin for several Atlassian products affecting versions 3.1.0 through 3.2.2 for Jira and Confluence, versions 2.4.0 through 3.0.3 for Bitbucket, and versions 2.4.0 through 2.5.2 for Bamboo. It allows locally disabled users to reactivate their accounts just by browsing the affected Jira/Confluence/Bitbucket/Bamboo instance, even when the applicable configuration option of the plugin has been disabled ("Reactivate inactive users"). Exploiting this vulnerability requires an attacker to be authorized by the identity provider and requires that the plugin's configuration option "User Update Method" have the "Update from SAML Attributes" value.
+
CVE-2019-14261
Date: 25-07-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14261
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-14261
🔗
Status: Candidate
Description: An issue was discovered on ABUS Secvest FUAA50000 3.01.01 devices. Due to an insufficient implementation of jamming detection, an attacker is able to suppress correctly received RF messages sent between wireless peripheral components, e.g., wireless detectors or remote controls, and the ABUS Secvest alarm central. An attacker is able to perform a "reactive jamming" attack. The reactive jamming simply detects the start of a RF message sent by a component of the ABUS Secvest wireless alarm system, for instance a wireless motion detector (FUBW50000) or a remote control (FUBE50014 or FUBE50015), and overlays it with random data before the original RF message ends. Thereby, the receiver (alarm central) is not able to properly decode the original transmitted signal. This enables an attacker to suppress correctly received RF messages of the wireless alarm system in an unauthorized manner, for instance status messages sent by a detector indicating an intrusion.
+
CVE-2019-16770
Date: 24-09-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16770
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-16770
🔗
Status: Candidate
Description: In Puma before version 4.3.2, a poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack. If more keepalive connections to Puma are opened than there are threads available, additional connections will wait permanently if the attacker sends requests frequently enough.
+
CVE-2019-7176
Date: 29-01-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7176
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-7176
🔗
Status: Candidate
Description: An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2. It has Incorrect Access Control. Guest users are able to add reaction emojis on comments to which they have no visibility.
+
Netlify
+
CVE-2019-7551
Date: 06-02-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7551
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-7551
🔗
Status: Candidate
Description: Cantemo Portal before 3.2.13, 3.3.x before 3.3.8, and 3.4.x before 3.4.9 has XSS. Leveraging this vulnerability would enable performing actions as users, including administrative users. This could enable account creation and deletion as well as deletion of information contained within the app.
+
Netlify
+
CVE-2019-7551
Date: 06-02-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7551
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-7551
🔗
Status: Candidate
Description: Cantemo Portal before 3.2.13, 3.3.x before 3.3.8, and 3.4.x before 3.4.9 has XSS. Leveraging this vulnerability would enable performing actions as users, including administrative users. This could enable account creation and deletion as well as deletion of information contained within the app.
+
Gatsby
(v2.10.0)
+
Google Font API
+
Netlify
+
CVE-2019-7551
Date: 06-02-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7551
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-7551
🔗
Status: Candidate
Description: Cantemo Portal before 3.2.13, 3.3.x before 3.3.8, and 3.4.x before 3.4.9 has XSS. Leveraging this vulnerability would enable performing actions as users, including administrative users. This could enable account creation and deletion as well as deletion of information contained within the app.
+
React
+
CVE-2019-11284
Date: 18-04-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11284
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-11284
🔗
Status: Candidate
Description: Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to.
+
CVE-2019-12153
Date: 17-05-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12153
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-12153
🔗
Status: Candidate
Description: Lack of validation in the HTML parser in RealObjects PDFreactor before 10.1.10722 leads to SSRF, allowing attackers to access network or file resources on behalf of the server by supplying malicious HTML content.
+
CVE-2019-12154
Date: 17-05-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12154
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-12154
🔗
Status: Candidate
Description: XXE in the XML parser library in RealObjects PDFreactor before 10.1.10722 allows attackers to supply malicious XML content in externally referenced resources, leading to disclosure of local file contents and/or denial of service conditions.
+
CVE-2019-12164
Date: 17-05-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12164
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-12164
🔗
Status: Candidate
Description: ubuntu-server.js in Status React Native Desktop before v0.57.8_mobile_ui allows Remote Code Execution.
+
CVE-2019-13347
Date: 05-07-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13347
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-13347
🔗
Status: Candidate
Description: An issue was discovered in the SAML Single Sign On (SSO) plugin for several Atlassian products affecting versions 3.1.0 through 3.2.2 for Jira and Confluence, versions 2.4.0 through 3.0.3 for Bitbucket, and versions 2.4.0 through 2.5.2 for Bamboo. It allows locally disabled users to reactivate their accounts just by browsing the affected Jira/Confluence/Bitbucket/Bamboo instance, even when the applicable configuration option of the plugin has been disabled ("Reactivate inactive users"). Exploiting this vulnerability requires an attacker to be authorized by the identity provider and requires that the plugin's configuration option "User Update Method" have the "Update from SAML Attributes" value.
+
CVE-2019-14261
Date: 25-07-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14261
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-14261
🔗
Status: Candidate
Description: An issue was discovered on ABUS Secvest FUAA50000 3.01.01 devices. Due to an insufficient implementation of jamming detection, an attacker is able to suppress correctly received RF messages sent between wireless peripheral components, e.g., wireless detectors or remote controls, and the ABUS Secvest alarm central. An attacker is able to perform a "reactive jamming" attack. The reactive jamming simply detects the start of a RF message sent by a component of the ABUS Secvest wireless alarm system, for instance a wireless motion detector (FUBW50000) or a remote control (FUBE50014 or FUBE50015), and overlays it with random data before the original RF message ends. Thereby, the receiver (alarm central) is not able to properly decode the original transmitted signal. This enables an attacker to suppress correctly received RF messages of the wireless alarm system in an unauthorized manner, for instance status messages sent by a detector indicating an intrusion.
+
CVE-2019-16770
Date: 24-09-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16770
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-16770
🔗
Status: Candidate
Description: In Puma before version 4.3.2, a poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack. If more keepalive connections to Puma are opened than there are threads available, additional connections will wait permanently if the attacker sends requests frequently enough.
+
CVE-2019-7176
Date: 29-01-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7176
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-7176
🔗
Status: Candidate
Description: An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2. It has Incorrect Access Control. Guest users are able to add reaction emojis on comments to which they have no visibility.
+
webpack
+
Netlify
+
CVE-2019-7551
Date: 06-02-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7551
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-7551
🔗
Status: Candidate
Description: Cantemo Portal before 3.2.13, 3.3.x before 3.3.8, and 3.4.x before 3.4.9 has XSS. Leveraging this vulnerability would enable performing actions as users, including administrative users. This could enable account creation and deletion as well as deletion of information contained within the app.
+
Netlify
+
CVE-2019-7551
Date: 06-02-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7551
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-7551
🔗
Status: Candidate
Description: Cantemo Portal before 3.2.13, 3.3.x before 3.3.8, and 3.4.x before 3.4.9 has XSS. Leveraging this vulnerability would enable performing actions as users, including administrative users. This could enable account creation and deletion as well as deletion of information contained within the app.
+
Netlify
+
CVE-2019-7551
Date: 06-02-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7551
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-7551
🔗
Status: Candidate
Description: Cantemo Portal before 3.2.13, 3.3.x before 3.3.8, and 3.4.x before 3.4.9 has XSS. Leveraging this vulnerability would enable performing actions as users, including administrative users. This could enable account creation and deletion as well as deletion of information contained within the app.
+
Netlify
+
CVE-2019-7551
Date: 06-02-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7551
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-7551
🔗
Status: Candidate
Description: Cantemo Portal before 3.2.13, 3.3.x before 3.3.8, and 3.4.x before 3.4.9 has XSS. Leveraging this vulnerability would enable performing actions as users, including administrative users. This could enable account creation and deletion as well as deletion of information contained within the app.
+
Netlify
+
CVE-2019-7551
Date: 06-02-2019
cve-mitre URL:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7551
🔗
nvd-nist URL:
https://nvd.nist.gov/vuln/detail/CVE-2019-7551
🔗
Status: Candidate
Description: Cantemo Portal before 3.2.13, 3.3.x before 3.3.8, and 3.4.x before 3.4.9 has XSS. Leveraging this vulnerability would enable performing actions as users, including administrative users. This could enable account creation and deletion as well as deletion of information contained within the app.