|
219261
|
5.5 |
MEDIUM
Local
|
linux fedoraproject debian canonical opensuse netapp
|
linux_kernel fedora debian_linux ubuntu_linux leap vasa_provider_for_clustered_data_ontap solidfire hci_management_node snapprotect active_iq_unified_manager_for_vmware_vsp…
|
A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local a…
|
-
|
CVE-2019-3882
|
2024-11-21 13:42 |
2019-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219262
|
3.8 |
LOW
Network
|
redhat
|
keycloak
|
Keycloak up to version 6.0.0 allows the end user token (access or id token JWT) to be used as the session cookie for browser sessions for OIDC. As a result an attacker with access to service provider…
|
CWE-200
Information Exposure
|
CVE-2019-3868
|
2024-11-21 13:42 |
2019-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219263
|
9.8 |
CRITICAL
Network
|
pivotal_software
|
application_service
|
Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21, versions 667.0.x prior to 667.0.7, contain an invitation service that accepts HTTP. A remote unau…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-3793
|
2024-11-21 13:42 |
2019-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219264
|
6.5 |
MEDIUM
Network
|
cloudfoundry
|
routing_release
|
Cloud Foundry Routing Release, all versions prior to 0.188.0, contains a vulnerability that can hijack the traffic to route services hosted outside the platform. A user with space developer permissio…
|
CWE-269
Improper Privilege Management
|
CVE-2019-3789
|
2024-11-21 13:42 |
2019-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219265
|
7.1 |
HIGH
Network
|
cloudfoundry
|
bosh_backup_and_restore
|
Cloud Foundry BOSH Backup and Restore CLI, all versions prior to 1.5.0, does not check the authenticity of backup scripts in BOSH. A remote authenticated malicious user can modify the metadata file o…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-3786
|
2024-11-21 13:42 |
2019-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219266
|
5.9 |
MEDIUM
Network
|
mercurial redhat debian
|
mercurial enterprise_linux debian_linux
|
A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.
|
CWE-59
Link Following
|
CVE-2019-3902
|
2024-11-21 13:42 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219267
|
9.8 |
CRITICAL
Network
|
redhat heketi_project
|
openshift_container_platform heketi
|
It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift …
|
-
|
CVE-2019-3899
|
2024-11-21 13:42 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219268
|
4.7 |
MEDIUM
Local
|
linux debian netapp
|
linux_kernel debian_linux vasa_provider_for_clustered_data_ontap solidfire hci_management_node snapprotect active_iq_unified_manager_for_vmware_vsphere virtual_storage_console_fo…
|
A race condition in perf_event_open() allows local attackers to leak sensitive data from setuid programs. As no relevant locks (in particular the cred_guard_mutex) are held during the ptrace_may_acce…
|
-
|
CVE-2019-3901
|
2024-11-21 13:42 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219269
|
8.0 |
HIGH
Adjacent
|
dell
|
supportassist
|
Dell SupportAssist Client versions prior to 3.2.0.90 contain a remote code execution vulnerability. An unauthenticated attacker, sharing the network access layer with the vulnerable system, can compr…
|
NVD-CWE-noinfo
|
CVE-2019-3719
|
2024-11-21 13:42 |
2019-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219270
|
8.8 |
HIGH
Network
|
dell
|
supportassist
|
Dell SupportAssist Client versions prior to 3.2.0.90 contain an improper origin validation vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to attempt CS…
|
CWE-352
Origin Validation Error
|
CVE-2019-3718
|
2024-11-21 13:42 |
2019-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|