|
219401
|
6.1 |
MEDIUM
Network
|
labkey
|
labkey_server
|
Reflected cross-site scripting (XSS) vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 allows an unauthenticated remote attacker to inject arbitrary javascript via the onerror …
|
CWE-79
Cross-site Scripting
|
CVE-2019-3911
|
2024-11-21 13:42 |
2019-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219402
|
9.8 |
CRITICAL
Network
|
powerdns
|
recursor
|
An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authoritative servers with the AA flag not set were not properl…
|
CWE-295
Improper Certificate Validation
|
CVE-2019-3807
|
2024-11-21 13:42 |
2019-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219403
|
8.1 |
HIGH
Network
|
powerdns
|
recursor
|
An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly…
|
NVD-CWE-noinfo
|
CVE-2019-3806
|
2024-11-21 13:42 |
2019-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219404
|
8.1 |
HIGH
Network
|
debian canonical netapp
|
advanced_package_tool ubuntu_linux debian_linux element_software active_iq
|
Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code executio…
|
NVD-CWE-noinfo
|
CVE-2019-3462
|
2024-11-21 13:42 |
2019-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219405
|
7.1 |
HIGH
Local
|
mcafee
|
total_protection
|
Exploitation of Privilege/Trust vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0.R18 allows local users to bypass product self-protection, tamper with policies…
|
NVD-CWE-noinfo
|
CVE-2019-3593
|
2024-11-21 13:42 |
2019-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219406
|
3.3 |
LOW
Local
|
redhat debian
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_eus enterprise_linux_server_aus openshift_container_platform debian_linux
|
A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c does not free the memory allocated by set_i…
|
-
|
CVE-2019-3815
|
2024-11-21 13:42 |
2019-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219407
|
4.4 |
MEDIUM
Local
|
linux debian canonical opensuse
|
linux_kernel debian_linux ubuntu_linux leap
|
A flaw was found in the Linux kernel in the function hid_debug_events_read() in drivers/hid/hid-debug.c file which may enter an infinite loop with certain parameters passed from a userspace. A local …
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-3819
|
2024-11-21 13:42 |
2019-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219408
|
6.5 |
MEDIUM
Local
|
mcafee
|
total_protection
|
DLL Search Order Hijacking vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0.18 allows local users to execute arbitrary code via execution from a compromised fo…
|
CWE-426
Untrusted Search Path
|
CVE-2019-3587
|
2024-11-21 13:42 |
2019-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219409
|
6.0 |
MEDIUM
Local
|
mcafee
|
mvision_endpoint
|
Exploitation of Authentication vulnerability in MVision Endpoint in McAfee MVision Endpoint Prior to 1811 Update 1 (18.11.31.62) allows authenticated administrator users --> administrators to Remove …
|
CWE-287
Improper Authentication
|
CVE-2019-3584
|
2024-11-21 13:42 |
2019-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219410
|
9.8 |
CRITICAL
Network
|
pivotal_software
|
spring_batch
|
Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
|
CWE-611
XXE
|
CVE-2019-3774
|
2024-11-21 13:42 |
2019-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|