CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1087, CVE-2019-1088.
In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc. This issue exists because of an incomplete fix for CVE-2019-10255.
Computrols CBAS 18.0.0 mishandles password hashes. The approach is MD5 with a pw prefix, e.g., if the password is admin, it will calculate the MD5 hash of pwadmin and store it in a MySQL database.
Computrols CBAS 18.0.0 allows Authenticated Command Injection.
Computrols CBAS 18.0.0 allows Authentication Bypass.
Computrols CBAS 18.0.0 allows Authenticated Blind SQL Injection via the id GET parameter, as demonstrated by the index.php?m=servers&a=start_pulling&id= substring.
Computrols CBAS 18.0.0 has hard-coded encryption keys.
Computrols CBAS 18.0.0 has Default Credentials.
An elevation of privilege vulnerability exists in the way that the wlansvc.dll handles objects in memory, aka 'Windows WLAN Service Elevation of Privilege Vulnerability'.
Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.
