|
219711
|
9.8 |
CRITICAL
Network
|
dell
|
idrac7_firmware idrac8_firmware idrac9_firmware idrac6_firmware
|
Dell EMC iDRAC6 versions prior to 2.92, iDRAC7/iDRAC8 versions prior to 2.61.60.60, and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22 and 3.23.23.23 contain a stack-based buffer overflo…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-3705
|
2024-11-21 13:42 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219712
|
9.8 |
CRITICAL
Network
|
cloudfoundry
|
cf-deployment uaa_release credhub
|
Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker coul…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-3801
|
2024-11-21 13:42 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219713
|
6.1 |
MEDIUM
Network
|
cloudfoundry
|
uaa_release
|
Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri. Given a UAA client was configured with a wildcard in the redirect uri's subdomain, a …
|
CWE-601
Open Redirect
|
CVE-2019-3788
|
2024-11-21 13:42 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219714
|
7.5 |
HIGH
Network
|
dell
|
emc_openmanage_server_administrator
|
Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain an Improper Range Header Processing Vulnerability. A remote unauthenticated attacker may send crafted requests with ov…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-3721
|
2024-11-21 13:42 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219715
|
4.9 |
MEDIUM
Network
|
dell
|
emc_openmanage_server_administrator
|
Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain a Directory Traversal Vulnerability. A remote authenticated malicious user with admin privileges could potentially exp…
|
CWE-22
Path Traversal
|
CVE-2019-3720
|
2024-11-21 13:42 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219716
|
7.7 |
HIGH
Network
|
linux fedoraproject redhat debian canonical netapp oracle
|
linux_kernel fedora enterprise_linux debian_linux ubuntu_linux vasa_provider_for_clustered_data_ontap solidfire hci_management_node snapprotect active_iq_unified_manager_fo…
|
An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets f…
|
-
|
CVE-2019-3900
|
2024-11-21 13:42 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219717
|
5.5 |
MEDIUM
Local
|
linux fedoraproject debian canonical opensuse netapp
|
linux_kernel fedora debian_linux ubuntu_linux leap vasa_provider_for_clustered_data_ontap solidfire hci_management_node snapprotect active_iq_unified_manager_for_vmware_vsp…
|
A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local a…
|
-
|
CVE-2019-3882
|
2024-11-21 13:42 |
2019-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219718
|
3.8 |
LOW
Network
|
redhat
|
keycloak
|
Keycloak up to version 6.0.0 allows the end user token (access or id token JWT) to be used as the session cookie for browser sessions for OIDC. As a result an attacker with access to service provider…
|
CWE-200
Information Exposure
|
CVE-2019-3868
|
2024-11-21 13:42 |
2019-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219719
|
9.8 |
CRITICAL
Network
|
pivotal_software
|
application_service
|
Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21, versions 667.0.x prior to 667.0.7, contain an invitation service that accepts HTTP. A remote unau…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-3793
|
2024-11-21 13:42 |
2019-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219720
|
6.5 |
MEDIUM
Network
|
cloudfoundry
|
routing_release
|
Cloud Foundry Routing Release, all versions prior to 0.188.0, contains a vulnerability that can hijack the traffic to route services hosted outside the platform. A user with space developer permissio…
|
CWE-269
Improper Privilege Management
|
CVE-2019-3789
|
2024-11-21 13:42 |
2019-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|