|
219741
|
7.5 |
HIGH
Adjacent
|
verizon
|
fios_quantum_gateway_g1100_firmware
|
Authentication Bypass by Capture-replay vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an unauthenticated attacker with adjacent network access to intercept…
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2019-3915
|
2024-11-21 13:42 |
2019-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219742
|
4.4 |
MEDIUM
Local
|
mcafee
|
data_exchange_layer threat_intelligence_exchange
|
Information Disclosure vulnerability in McAfee DXL Platform and TIE Server in DXL prior to 5.0.1 HF2 and TIE prior to 2.3.1 HF1 allows Authenticated users to view sensitive information in plain text …
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2019-3612
|
2024-11-21 13:42 |
2019-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219743
|
7.0 |
HIGH
Local
|
systemd_project redhat fedoraproject debian
|
systemd enterprise_linux fedora debian_linux
|
In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular config…
|
CWE-863
Incorrect Authorization
|
CVE-2019-3842
|
2024-11-21 13:42 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219744
|
7.5 |
HIGH
Network
|
advantech
|
webaccess
|
Advantech WebAccess 8.3.4 allows unauthenticated, remote attackers to delete arbitrary files via IOCTL 10005 RPC.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-3941
|
2024-11-21 13:42 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219745
|
9.8 |
CRITICAL
Network
|
advantech
|
webaccess
|
Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unauthenticated, remote attacker can use this vulnerability to execute arbitrary code.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-3940
|
2024-11-21 13:42 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219746
|
4.9 |
MEDIUM
Network
|
theforeman redhat
|
foreman satellite
|
In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to the disclosure of the plaintext password or token for the affected compute resour…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-3893
|
2024-11-21 13:42 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219747
|
5.4 |
MEDIUM
Network
|
samba debian redhat fedoraproject opensuse
|
samba debian_linux enterprise_linux gluster_storage fedora leap
|
A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they…
|
CWE-22
Path Traversal
|
CVE-2019-3880
|
2024-11-21 13:42 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219748
|
5.6 |
MEDIUM
Local
|
linux fedoraproject canonical redhat
|
linux_kernel fedora ubuntu_linux enterprise_linux enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus enterprise_linux_for_real_time enterprise_linux_…
|
A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtualization enabled. In that, L1 guest could access L0's APIC register values via …
|
-
|
CVE-2019-3887
|
2024-11-21 13:42 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219749
|
6.1 |
MEDIUM
Local
|
samba fedoraproject synology
|
samba fedora diskstation_manager directory_server router_manager skynas_firmware vs960hd_firmware
|
A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the insta…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-3870
|
2024-11-21 13:42 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219750
|
5.3 |
MEDIUM
Network
|
vmware debian
|
spring_security debian_linux
|
Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a …
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2019-3795
|
2024-11-21 13:42 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|