|
219841
|
5.5 |
MEDIUM
Local
|
mcafee
|
true_key
|
Data Leakage Attacks vulnerability in Microsoft Windows client in McAfee True Key (TK) 3.1.9211.0 and earlier allows local users to expose confidential data via specially crafted malware.
|
CWE-200
Information Exposure
|
CVE-2019-3610
|
2024-11-21 13:42 |
2019-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219842
|
7.8 |
HIGH
Local
|
cloudfoundry
|
credhub_cli
|
Cloud Foundry CredHub CLI, versions prior to 2.2.1, inadvertently writes authentication credentials provided via environment variables to its persistent config file. A local authenticated malicious u…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-3782
|
2024-11-21 13:42 |
2019-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219843
|
5.4 |
MEDIUM
Network
|
tenable
|
nessus
|
Nessus versions 8.2.1 and earlier were found to contain a stored XSS vulnerability due to improper validation of user-supplied input. An authenticated, remote attacker could potentially exploit this …
|
CWE-79
Cross-site Scripting
|
CVE-2019-3923
|
2024-11-21 13:42 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219844
|
7.8 |
HIGH
Local
|
dell
|
emc_vnx2_firmware
|
VNX Control Station in Dell EMC VNX2 OE for File versions prior to 8.1.9.236 contains OS command injection vulnerability. Due to inadequate restriction configured in sudores, a local authenticated ma…
|
CWE-78
OS Command
|
CVE-2019-3704
|
2024-11-21 13:42 |
2019-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219845
|
6.4 |
MEDIUM
Physics
|
gnome canonical redhat
|
gnome_display_manager ubuntu_linux enterprise_linux
|
A vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could bypass the lock screen by selecting the timed login user and waiting for the timer…
|
CWE-287
Improper Authentication
|
CVE-2019-3825
|
2024-11-21 13:42 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219846
|
4.3 |
MEDIUM
Physics
|
gnome opensuse canonical
|
gnome-shell leap ubuntu_linux
|
It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An attacker with physical access to a locked workstation could invoke certai…
|
CWE-287
Improper Authentication
|
CVE-2019-3820
|
2024-11-21 13:42 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219847
|
9.8 |
CRITICAL
Network
|
pizzashack debian fedoraproject canonical
|
rssh debian_linux fedora ubuntu_linux
|
Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulti…
|
CWE-665
Improper Initialization
|
CVE-2019-3464
|
2024-11-21 13:42 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219848
|
9.8 |
CRITICAL
Network
|
pizzashack debian fedoraproject canonical
|
rssh debian_linux fedora ubuntu_linux
|
Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the ex…
|
CWE-88
Argument Injection
|
CVE-2019-3463
|
2024-11-21 13:42 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219849
|
7.5 |
HIGH
Network
|
haxx canonical debian netapp oracle
|
libcurl ubuntu_linux debian_linux clustered_data_ontap http_server secure_global_desktop communications_operations_monitor
|
libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL termi…
|
-
|
CVE-2019-3823
|
2024-11-21 13:42 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219850
|
9.8 |
CRITICAL
Network
|
haxx canonical debian netapp siemens oracle redhat
|
libcurl ubuntu_linux debian_linux snapcenter oncommand_workflow_automation oncommand_insight active_iq_unified_manager clustered_data_ontap sinema_remote_connect_client htt…
|
libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_mess…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-3822
|
2024-11-21 13:42 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|