|
219311
|
4.3 |
MEDIUM
Network
|
moodle fedoraproject
|
moodle fedora
|
A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page.
|
NVD-CWE-noinfo
|
CVE-2019-3851
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219312
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may…
|
CWE-601
Open Redirect
|
CVE-2019-3850
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219313
|
8.1 |
HIGH
Network
|
mod_auth_mellon_project fedoraproject redhat canonical
|
mod_auth_mellon fedora enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_eus e…
|
A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through authenticated users (with the require val…
|
CWE-287
Improper Authentication
|
CVE-2019-3878
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219314
|
8.8 |
HIGH
Network
|
moodle
|
moodle
|
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the…
|
CWE-269
Improper Privilege Management
|
CVE-2019-3849
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219315
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logg…
|
CWE-863
Incorrect Authorization
|
CVE-2019-3848
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219316
|
7.8 |
HIGH
Local
|
openstack redhat
|
ceilometer openstack
|
A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data to log files without DEBUG logging being activated.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-3830
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219317
|
6.1 |
MEDIUM
Network
|
prometheus redhat
|
prometheus openshift_container_platform
|
A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prome…
|
-
|
CVE-2019-3826
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219318
|
7.5 |
HIGH
Network
|
cockpit-project fedoraproject redhat
|
cockpit fedora virtualization
|
It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted re…
|
CWE-909
Missing Initialization of Resource
|
CVE-2019-3804
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219319
|
4.1 |
MEDIUM
Local
|
mcafee
|
network_security_manager
|
Data Leakage Attacks vulnerability in the web portal component when in an MDR pair in McAfee Network Security Management (NSM) 9.1 < 9.1.7.75 (Update 4) and 9.2 < 9.2.7.31 Update2 allows administrato…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2019-3606
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219320
|
9.8 |
CRITICAL
Network
|
mcafee
|
network_security_manager
|
Authentication Bypass vulnerability in McAfee Network Security Manager (NSM) 9.1 < 9.1.7.75.2 and 9.2 < 9.2.7.31 (9.2 Update 2) allows unauthenticated users to gain administrator rights via incorrect…
|
NVD-CWE-noinfo
|
CVE-2019-3597
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|