Skip to main content

CWE archive

CWE-1188 CVEs

Programmatic archive

317 CVEs tagged with CWE-118892 Critical, 129 High, 85 Medium, 11 Low, 0 Unrated.

CVE-2019-19251

Published Dec 10, 2019

The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without the use of SSL/TLS. Although there is an Enable SSL option,…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4621

Published Dec 9, 2019

IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account that is enabled if the IPMI LAN channel is enabled. A remote a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-2197

Published Nov 13, 2019

In processPhonebookAccess of CachedBluetoothDevice.java, there is a possible permission bypass due to an insecure default value. This could lead to local information disclosure of…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3278

Published Nov 7, 2019

frysk packages through 2008-08-05 as shipped in Red Hat Enterprise Linux 5 are built with an insecure RPATH set in the ELF header of multiple binaries in /usr/bin/f* (e.g. fcore,…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14222

Published Sep 5, 2019

An issue was discovered in Alfresco Community Edition versions 6.0 and lower. An unauthenticated, remote attacker could authenticate to Alfresco's Solr Web Admin Interface. The vu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-2131

Published Aug 20, 2019

An application with overlay permission can display overlays on top of settings UI. This could lead to local escalation of privilege with no additional execution privileges needed.…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-2120

Published Aug 20, 2019

In OatFileAssistant::GenerateOatFile of oat_file_assistant.cc, there is a possible file corruption issue due to an insecure default value. This could lead to local escalation of p…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-2043

Published May 8, 2019

In SmsDefaultDialog.onStart of SmsDefaultDialog.java, there is a possible escalation of privilege due to an overlay attack. This could lead to local escalation of privilege, grant…

CVSS 7.3 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2019-11618

Published Apr 30, 2019

doorGets 7.0 has a default administrator credential vulnerability. A remote attacker can use this vulnerability to gain administrator privileges for the creation and modification…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-7476

Published Apr 26, 2019

A vulnerability in SonicWall Global Management System (GMS), allow a remote user to gain access to the appliance using existing SSH key. This vulnerability affects GMS versions 9.…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-2041

Published Apr 19, 2019

In the configuration of NFC modules on certain devices, there is a possible failure to distinguish individual devices due to an insecure default value. This could lead to local es…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2018-19275

Published Apr 2, 2019

The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remote attackers to gain unauthorized access…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-17497

Published Mar 21, 2019

eVisitorPass contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application.

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 251-275 of 317 CVEsPage 11 of 13