|
219811
|
4.7 |
MEDIUM
Local
|
linux debian netapp
|
linux_kernel debian_linux vasa_provider_for_clustered_data_ontap solidfire hci_management_node snapprotect active_iq_unified_manager_for_vmware_vsphere virtual_storage_console_fo…
|
A race condition in perf_event_open() allows local attackers to leak sensitive data from setuid programs. As no relevant locks (in particular the cred_guard_mutex) are held during the ptrace_may_acce…
|
-
|
CVE-2019-3901
|
2024-11-21 13:42 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219812
|
8.0 |
HIGH
Adjacent
|
dell
|
supportassist
|
Dell SupportAssist Client versions prior to 3.2.0.90 contain a remote code execution vulnerability. An unauthenticated attacker, sharing the network access layer with the vulnerable system, can compr…
|
NVD-CWE-noinfo
|
CVE-2019-3719
|
2024-11-21 13:42 |
2019-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219813
|
8.8 |
HIGH
Network
|
dell
|
supportassist
|
Dell SupportAssist Client versions prior to 3.2.0.90 contain an improper origin validation vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to attempt CS…
|
CWE-352
Origin Validation Error
|
CVE-2019-3718
|
2024-11-21 13:42 |
2019-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219814
|
7.5 |
HIGH
Network
|
clusterlabs canonical fedoraproject
|
pacemaker ubuntu_linux fedora
|
A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in certain sensitive information to be leaked via the system logs.
|
CWE-416
Use After Free
|
CVE-2019-3885
|
2024-11-21 13:42 |
2019-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219815
|
8.8 |
HIGH
Network
|
atlassian
|
confluence confluence_server
|
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to crea…
|
CWE-22
Path Traversal
|
CVE-2019-3398
|
2024-11-21 13:42 |
2019-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219816
|
7.5 |
HIGH
Network
|
cloudfoundry
|
capi-release
|
Cloud Foundry Cloud Controller API Release, versions prior to 1.79.0, contains improper authentication when validating user permissions. A remote authenticated malicious user with the ability to crea…
|
CWE-287
Improper Authentication
|
CVE-2019-3798
|
2024-11-21 13:42 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219817
|
9.6 |
CRITICAL
Network
|
dell
|
emc_isilonsd_management_server
|
IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while registering vCenter servers. A remote attacker can trick an admin user to potentially exploit this vulnerability t…
|
CWE-79
Cross-site Scripting
|
CVE-2019-3709
|
2024-11-21 13:42 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219818
|
9.6 |
CRITICAL
Network
|
dell
|
emc_isilonsd_management_server
|
IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while uploading an OVA file. A remote attacker can trick an admin user to potentially exploit this vulnerability to exec…
|
CWE-79
Cross-site Scripting
|
CVE-2019-3708
|
2024-11-21 13:42 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219819
|
7.5 |
HIGH
Network
|
fedoraproject debian redhat
|
389_directory_server debian_linux enterprise_linux
|
In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2019-3883
|
2024-11-21 13:42 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219820
|
7.8 |
HIGH
Local
|
redhat
|
satellite
|
It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin database. A malicious user with local access to a Sa…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-3891
|
2024-11-21 13:42 |
2019-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|