|
219751
|
5.4 |
MEDIUM
Adjacent
|
redhat opensuse fedoraproject
|
libvirt leap fedora
|
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing u…
|
-
|
CVE-2019-3886
|
2024-11-21 13:42 |
2019-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219752
|
7.5 |
HIGH
Network
|
pivotal_software
|
concourse
|
Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a version identifier that can carry a SQL injection payload to the Concourse serv…
|
CWE-89
SQL Injection
|
CVE-2019-3792
|
2024-11-21 13:42 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219753
|
7.5 |
HIGH
Network
|
microfocus
|
content_manager
|
An unauthenticated file upload vulnerability has been identified in the Web Client component of Micro Focus Content Manager 9.1, 9.2, and 9.3 when configured to use the ADFS authentication method. Th…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-3489
|
2024-11-21 13:42 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219754
|
6.3 |
MEDIUM
Network
|
redhat
|
openshift_container_platform
|
A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing X-Frame-Options and CSRF protections. If not otherw…
|
-
|
CVE-2019-3876
|
2024-11-21 13:42 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219755
|
7.5 |
HIGH
Network
|
gnu fedoraproject opensuse
|
gnutls fedora leap
|
It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2019-3836
|
2024-11-21 13:42 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219756
|
8.1 |
HIGH
Network
|
dell
|
emc_networking_os10
|
Dell EMC Networking OS10 versions prior to 10.4.3 contain a cryptographic key vulnerability due to an underlying application using undocumented, pre-installed X.509v3 key/certificate pairs. An unauth…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-3710
|
2024-11-21 13:42 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219757
|
7.2 |
HIGH
Network
|
redhat
|
ansible_tower
|
When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks co…
|
CWE-200
Information Exposure
|
CVE-2019-3869
|
2024-11-21 13:42 |
2019-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219758
|
7.5 |
HIGH
Network
|
gnu fedoraproject
|
gnutls fedora
|
A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifi…
|
CWE-415 CWE-416
Double Free Use After Free
|
CVE-2019-3829
|
2024-11-21 13:42 |
2019-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219759
|
6.1 |
MEDIUM
Network
|
mod_auth_mellon_project fedoraproject redhat canonical
|
mod_auth_mellon fedora enterprise_linux ubuntu_linux
|
A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the brows…
|
CWE-601
Open Redirect
|
CVE-2019-3877
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219760
|
4.8 |
MEDIUM
Network
|
moodle
|
moodle
|
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboar…
|
CWE-79
Cross-site Scripting
|
CVE-2019-3847
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|