Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2019-09-12 CVE-2019-10397 Cleartext Transmission of Sensitive Information vulnerability in Jenkins Aqua Security Severless Scanner
Jenkins Aqua Security Serverless Scanner Plugin 1.0.4 and earlier transmitted configured passwords in plain text as part of job configuration forms, potentially resulting in their exposure.
network
high complexity
jenkins CWE-319
3.1
2019-09-10 CVE-2019-1563 Information Exposure Through Discrepancy vulnerability in Openssl
In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key, using a Bleichenbacher padding oracle attack.
network
high complexity
openssl CWE-203
3.7
2019-09-10 CVE-2019-0353 Unspecified vulnerability in SAP Business ONE Client 9.2/9.3
Under certain conditions SAP Business One client (B1_ON_HANA, SAP-M-BO), before versions 9.2 and 9.3, allows an attacker to access information which would otherwise be restricted.
local
low complexity
sap
3.3
2019-09-09 CVE-2019-7176 Unspecified vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2.
network
high complexity
gitlab
3.7
2019-09-09 CVE-2019-16183 Incorrect Default Permissions vulnerability in Limesurvey
In Limesurvey before 3.17.14, admin users can run an integrity check without proper permissions.
network
low complexity
limesurvey CWE-276
2.7
2019-09-09 CVE-2019-16181 Unspecified vulnerability in Limesurvey
In Limesurvey before 3.17.14, admin users can mark other users' notifications as read.
network
low complexity
limesurvey
2.7
2019-09-09 CVE-2019-5461 Improper Input Validation vulnerability in Gitlab
An input validation problem was discovered in the GitHub service integration which could result in an attacker being able to make arbitrary POST requests in a GitLab instance's internal network.
low complexity
gitlab CWE-20
3.5
2019-09-06 CVE-2019-9455 Reachable Assertion vulnerability in multiple products
In the Android kernel in the video driver there is a kernel pointer leak due to a WARN_ON statement.
local
low complexity
google opensuse CWE-617
2.3
2019-09-04 CVE-2019-15919 Use After Free vulnerability in multiple products
An issue was discovered in the Linux kernel before 5.0.10.
local
low complexity
linux opensuse CWE-416
3.3
2019-09-04 CVE-2019-10988 Unspecified vulnerability in Philips HDI 4000 Firmware
In Philips HDI 4000 Ultrasound Systems, all versions running on old, unsupported operating systems such as Windows 2000, the HDI 4000 Ultrasound System is built on an old operating system that is no longer supported.
local
low complexity
philips
3.4