|
220021
|
5.6 |
MEDIUM
Local
|
linux fedoraproject canonical redhat
|
linux_kernel fedora ubuntu_linux enterprise_linux enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus enterprise_linux_for_real_time enterprise_linux_…
|
A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtualization enabled. In that, L1 guest could access L0's APIC register values via …
|
-
|
CVE-2019-3887
|
2024-11-21 13:42 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220022
|
6.1 |
MEDIUM
Local
|
samba fedoraproject synology
|
samba fedora diskstation_manager directory_server router_manager skynas_firmware vs960hd_firmware
|
A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the insta…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-3870
|
2024-11-21 13:42 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220023
|
5.3 |
MEDIUM
Network
|
vmware debian
|
spring_security debian_linux
|
Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a …
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2019-3795
|
2024-11-21 13:42 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220024
|
5.4 |
MEDIUM
Adjacent
|
redhat opensuse fedoraproject
|
libvirt leap fedora
|
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing u…
|
-
|
CVE-2019-3886
|
2024-11-21 13:42 |
2019-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220025
|
7.5 |
HIGH
Network
|
pivotal_software
|
concourse
|
Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a version identifier that can carry a SQL injection payload to the Concourse serv…
|
CWE-89
SQL Injection
|
CVE-2019-3792
|
2024-11-21 13:42 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220026
|
7.5 |
HIGH
Network
|
microfocus
|
content_manager
|
An unauthenticated file upload vulnerability has been identified in the Web Client component of Micro Focus Content Manager 9.1, 9.2, and 9.3 when configured to use the ADFS authentication method. Th…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-3489
|
2024-11-21 13:42 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220027
|
6.3 |
MEDIUM
Network
|
redhat
|
openshift_container_platform
|
A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing X-Frame-Options and CSRF protections. If not otherw…
|
-
|
CVE-2019-3876
|
2024-11-21 13:42 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220028
|
7.5 |
HIGH
Network
|
gnu fedoraproject opensuse
|
gnutls fedora leap
|
It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2019-3836
|
2024-11-21 13:42 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220029
|
8.1 |
HIGH
Network
|
dell
|
emc_networking_os10
|
Dell EMC Networking OS10 versions prior to 10.4.3 contain a cryptographic key vulnerability due to an underlying application using undocumented, pre-installed X.509v3 key/certificate pairs. An unauth…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-3710
|
2024-11-21 13:42 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220030
|
7.2 |
HIGH
Network
|
redhat
|
ansible_tower
|
When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks co…
|
CWE-200
Information Exposure
|
CVE-2019-3869
|
2024-11-21 13:42 |
2019-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|