|
219391
|
9.8 |
CRITICAL
Network
|
pizzashack debian fedoraproject canonical
|
rssh debian_linux fedora ubuntu_linux
|
Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulti…
|
CWE-665
Improper Initialization
|
CVE-2019-3464
|
2024-11-21 13:42 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219392
|
9.8 |
CRITICAL
Network
|
pizzashack debian fedoraproject canonical
|
rssh debian_linux fedora ubuntu_linux
|
Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the ex…
|
CWE-88
Argument Injection
|
CVE-2019-3463
|
2024-11-21 13:42 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219393
|
7.5 |
HIGH
Network
|
haxx canonical debian netapp oracle
|
libcurl ubuntu_linux debian_linux clustered_data_ontap http_server secure_global_desktop communications_operations_monitor
|
libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL termi…
|
-
|
CVE-2019-3823
|
2024-11-21 13:42 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219394
|
9.8 |
CRITICAL
Network
|
haxx canonical debian netapp siemens oracle redhat
|
libcurl ubuntu_linux debian_linux snapcenter oncommand_workflow_automation oncommand_insight active_iq_unified_manager clustered_data_ontap sinema_remote_connect_client htt…
|
libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_mess…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-3822
|
2024-11-21 13:42 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219395
|
7.5 |
HIGH
Network
|
redhat kube-rbac-proxy_project
|
openshift_container_platform kube-rbac-proxy
|
The kube-rbac-proxy container before version 0.4.1 as used in Red Hat OpenShift Container Platform does not honor TLS configurations, allowing for use of insecure ciphers and TLS 1.0. An attacker cou…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-3818
|
2024-11-21 13:42 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219396
|
7.0 |
HIGH
Local
|
debian
|
tmpreaper debian_linux
|
Debian tmpreaper version 1.6.13+nmu1 has a race condition when doing a (bind) mount via rename() which could result in local privilege escalation. Mounting via rename() could potentially lead to a fi…
|
CWE-362
Race Condition
|
CVE-2019-3461
|
2024-11-21 13:42 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219397
|
7.5 |
HIGH
Adjacent
|
spice_project redhat debian canonical
|
spice enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_eus enterprise_linux_server_aus debian_lin…
|
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-executi…
|
CWE-193
Off-by-one Error
|
CVE-2019-3813
|
2024-11-21 13:42 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219398
|
8.8 |
HIGH
Network
|
mcafee
|
epolicy_orchestrator
|
Cross-Site Request Forgery (CSRF) vulnerability in McAfee ePO (legacy) Cloud allows unauthenticated users to perform unintended ePO actions using an authenticated user's session via unspecified vecto…
|
CWE-352
Origin Validation Error
|
CVE-2019-3604
|
2024-11-21 13:42 |
2019-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219399
|
4.9 |
MEDIUM
Network
|
labkey
|
labkey_server
|
Command manipulation in LabKey Server Community Edition before 18.3.0-61806.763 allows an authenticated remote attacker to unmount any drive on the system leading to denial of service.
|
CWE-78
OS Command
|
CVE-2019-3913
|
2024-11-21 13:42 |
2019-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219400
|
6.1 |
MEDIUM
Network
|
labkey
|
labkey_server
|
An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL parameter allows an unauthenticated remote attacker to redirect users to arbitrary w…
|
CWE-601
Open Redirect
|
CVE-2019-3912
|
2024-11-21 13:42 |
2019-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|