|
981
|
6.5
3.3
|
MEDIUM
Adjacent
|
A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-3459
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 13:42
2019-04-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
982
|
6.1
4.9
|
MEDIUM
Local
|
It was found that the net_dma code in tcp_recvmsg() in the 2.6.32 kernel as shipped in RHEL6 is thread-unsafe. So an unprivileged multi-threaded userspace application calling recvmsg() for the same n…
|
CWE-362 CWE-401
Race Condition Missing Release of Memory after Effective Lifetime
|
CVE-2019-3837
|
cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 13:42
2019-04-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
983
|
7.0
4.4
|
HIGH
Local
|
In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular config…
|
CWE-863
Incorrect Authorization
|
CVE-2019-3842
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 13:42
2019-04-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
984
|
5.4
5.5
|
MEDIUM
Network
|
A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they…
|
CWE-22
Path Traversal
|
CVE-2019-3880
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 13:42
2019-04-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
985
|
5.6
4.7
|
MEDIUM
Local
|
A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtualization enabled. In that, L1 guest could access L0's APIC register values via …
|
-
|
CVE-2019-3887
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 13:42
2019-04-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
986
|
6.5
4.0
|
MEDIUM
Network
|
A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tam…
|
NVD-CWE-noinfo
|
CVE-2019-0757
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 13:17
2019-04-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
987
|
7.8
7.2
|
HIGH
Local
|
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scrip…
|
CWE-416
Use After Free
|
CVE-2019-0211
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 13:16
2019-04-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
988
|
7.5
6.0
|
HIGH
Network
|
In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another usern…
|
CWE-362
Race Condition
|
CVE-2019-0217
|
cpe:2.3:o:redhat:enterprise_linux:-:*
|
|
|
|
|
2024-11-21 13:16
2019-04-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
989
|
9.8
7.5
|
CRITICAL
Network
|
Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege and/or denial of service via network access.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-0160
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 13:16
2019-03-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
990
|
6.1
4.3
|
MEDIUM
Network
|
A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the brows…
|
CWE-601
Open Redirect
|
CVE-2019-3877
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 13:42
2019-03-27
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|