|
219251
|
7.8 |
HIGH
Local
|
systemd_project canonical netapp
|
systemd ubuntu_linux solidfire hci_management_node snapprotect cn1610_firmware
|
It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by the service transi…
|
-
|
CVE-2019-3844
|
2024-11-21 13:42 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219252
|
7.8 |
HIGH
Local
|
systemd_project fedoraproject canonical netapp
|
systemd fedora ubuntu_linux solidfire hci_management_node snapprotect cn1610_firmware
|
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminate…
|
CWE-269
Improper Privilege Management
|
CVE-2019-3843
|
2024-11-21 13:42 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219253
|
9.8 |
CRITICAL
Network
|
dell
|
idrac9_firmware
|
Dell EMC iDRAC9 versions prior to 3.30.30.30 contain an authentication bypass vulnerability. A remote attacker may potentially exploit this vulnerability to bypass authentication and gain access to t…
|
NVD-CWE-noinfo
|
CVE-2019-3707
|
2024-11-21 13:42 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219254
|
9.8 |
CRITICAL
Network
|
dell
|
idrac9_firmware
|
Dell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22 and 3.21.25.22 contain an authentication bypass vulnerability. A remote attacker may potentially exploit this vulnerability to byp…
|
NVD-CWE-noinfo
|
CVE-2019-3706
|
2024-11-21 13:42 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219255
|
9.8 |
CRITICAL
Network
|
dell
|
idrac7_firmware idrac8_firmware idrac9_firmware idrac6_firmware
|
Dell EMC iDRAC6 versions prior to 2.92, iDRAC7/iDRAC8 versions prior to 2.61.60.60, and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22 and 3.23.23.23 contain a stack-based buffer overflo…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-3705
|
2024-11-21 13:42 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219256
|
9.8 |
CRITICAL
Network
|
cloudfoundry
|
cf-deployment uaa_release credhub
|
Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker coul…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-3801
|
2024-11-21 13:42 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219257
|
6.1 |
MEDIUM
Network
|
cloudfoundry
|
uaa_release
|
Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri. Given a UAA client was configured with a wildcard in the redirect uri's subdomain, a …
|
CWE-601
Open Redirect
|
CVE-2019-3788
|
2024-11-21 13:42 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219258
|
7.5 |
HIGH
Network
|
dell
|
emc_openmanage_server_administrator
|
Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain an Improper Range Header Processing Vulnerability. A remote unauthenticated attacker may send crafted requests with ov…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-3721
|
2024-11-21 13:42 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219259
|
4.9 |
MEDIUM
Network
|
dell
|
emc_openmanage_server_administrator
|
Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain a Directory Traversal Vulnerability. A remote authenticated malicious user with admin privileges could potentially exp…
|
CWE-22
Path Traversal
|
CVE-2019-3720
|
2024-11-21 13:42 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219260
|
7.7 |
HIGH
Network
|
linux fedoraproject redhat debian canonical netapp oracle
|
linux_kernel fedora enterprise_linux debian_linux ubuntu_linux vasa_provider_for_clustered_data_ontap solidfire hci_management_node snapprotect active_iq_unified_manager_fo…
|
An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets f…
|
-
|
CVE-2019-3900
|
2024-11-21 13:42 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|