|
219271
|
7.5 |
HIGH
Network
|
clusterlabs canonical fedoraproject
|
pacemaker ubuntu_linux fedora
|
A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in certain sensitive information to be leaked via the system logs.
|
CWE-416
Use After Free
|
CVE-2019-3885
|
2024-11-21 13:42 |
2019-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219272
|
8.8 |
HIGH
Network
|
atlassian
|
confluence confluence_server
|
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to crea…
|
CWE-22
Path Traversal
|
CVE-2019-3398
|
2024-11-21 13:42 |
2019-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219273
|
7.5 |
HIGH
Network
|
cloudfoundry
|
capi-release
|
Cloud Foundry Cloud Controller API Release, versions prior to 1.79.0, contains improper authentication when validating user permissions. A remote authenticated malicious user with the ability to crea…
|
CWE-287
Improper Authentication
|
CVE-2019-3798
|
2024-11-21 13:42 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219274
|
9.6 |
CRITICAL
Network
|
dell
|
emc_isilonsd_management_server
|
IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while registering vCenter servers. A remote attacker can trick an admin user to potentially exploit this vulnerability t…
|
CWE-79
Cross-site Scripting
|
CVE-2019-3709
|
2024-11-21 13:42 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219275
|
9.6 |
CRITICAL
Network
|
dell
|
emc_isilonsd_management_server
|
IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while uploading an OVA file. A remote attacker can trick an admin user to potentially exploit this vulnerability to exec…
|
CWE-79
Cross-site Scripting
|
CVE-2019-3708
|
2024-11-21 13:42 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219276
|
7.5 |
HIGH
Network
|
fedoraproject debian redhat
|
389_directory_server debian_linux enterprise_linux
|
In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2019-3883
|
2024-11-21 13:42 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219277
|
7.8 |
HIGH
Local
|
redhat
|
satellite
|
It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin database. A malicious user with local access to a Sa…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-3891
|
2024-11-21 13:42 |
2019-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219278
|
6.5 |
MEDIUM
Adjacent
|
linux canonical debian redhat
|
linux_kernel ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_for_real_time enterprise_linux_for_real_time…
|
A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux kernel before 5.1-rc1.
|
CWE-20
Improper Input Validation
|
CVE-2019-3460
|
2024-11-21 13:42 |
2019-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219279
|
6.5 |
MEDIUM
Adjacent
|
linux canonical redhat debian
|
linux_kernel ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server enterprise_linux_for_real_time enterprise_linux_for_real_…
|
A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-3459
|
2024-11-21 13:42 |
2019-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219280
|
7.5 |
HIGH
Network
|
verizon
|
fios_quantum_gateway_g1100_firmware
|
Information disclosure vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an remote, unauthenticated attacker to retrieve the value of the password salt by simp…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2019-3916
|
2024-11-21 13:42 |
2019-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|