|
219331
|
6.8 |
MEDIUM
Network
|
kubevirt
|
containerized_data_importer
|
Kubevirt/virt-cdi-importer, versions 1.4.0 to 1.5.3 inclusive, were reported to disable TLS certificate validation when importing data into PVCs from container registries. This could enable man-in-th…
|
CWE-295
Improper Certificate Validation
|
CVE-2019-3841
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219332
|
6.7 |
MEDIUM
Local
|
ovirt redhat
|
vdsm gluster_storage
|
A vulnerability was discovered in vdsm, version 4.19 through 4.30.3 and 4.30.5 through 4.30.8. The systemd_run function exposed to the vdsm system user could be abused to execute arbitrary commands a…
|
NVD-CWE-Other
|
CVE-2019-3831
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219333
|
8.8 |
HIGH
Network
|
libssh2 debian netapp opensuse redhat
|
libssh2 debian_linux ontap_select_deploy_administration_utility leap enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus …
|
A flaw was found in libssh2 before 1.8.1. A server could send a multiple keyboard interactive response messages whose total length are greater than unsigned char max characters. This value is used as…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-3863
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219334
|
7.0 |
HIGH
Local
|
gnome
|
gvfs
|
An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users without asking for password when no authe…
|
CWE-863
Incorrect Authorization
|
CVE-2019-3827
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219335
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included a…
|
CWE-79
Cross-site Scripting
|
CVE-2019-3810
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219336
|
10.0 |
CRITICAL
Network
|
moodle
|
moodle
|
A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Ba…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-3809
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219337
|
5.4 |
MEDIUM
Network
|
moodle
|
moodle
|
A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned …
|
CWE-79
Cross-site Scripting
|
CVE-2019-3808
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219338
|
7.8 |
HIGH
Local
|
hp
|
arcsight_logger
|
Mitigates a remote code execution issue in ArcSight Logger versions prior to 6.7.
|
NVD-CWE-noinfo
|
CVE-2019-3484
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219339
|
6.5 |
MEDIUM
Network
|
hp
|
arcsight_logger
|
Mitigates a potential information leakage issue in ArcSight Logger versions prior to 6.7.
|
NVD-CWE-noinfo
|
CVE-2019-3483
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219340
|
6.5 |
MEDIUM
Network
|
hp
|
arcsight_logger
|
Mitigates a directory traversal issue in ArcSight Logger versions prior to 6.7.
|
CWE-22
Path Traversal
|
CVE-2019-3482
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|