|
219821
|
6.5 |
MEDIUM
Adjacent
|
linux canonical debian redhat
|
linux_kernel ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_for_real_time enterprise_linux_for_real_time…
|
A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux kernel before 5.1-rc1.
|
CWE-20
Improper Input Validation
|
CVE-2019-3460
|
2024-11-21 13:42 |
2019-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219822
|
6.5 |
MEDIUM
Adjacent
|
linux canonical redhat debian
|
linux_kernel ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server enterprise_linux_for_real_time enterprise_linux_for_real_…
|
A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-3459
|
2024-11-21 13:42 |
2019-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219823
|
7.5 |
HIGH
Network
|
verizon
|
fios_quantum_gateway_g1100_firmware
|
Information disclosure vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an remote, unauthenticated attacker to retrieve the value of the password salt by simp…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2019-3916
|
2024-11-21 13:42 |
2019-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219824
|
8.0 |
HIGH
Adjacent
|
redhat
|
satellite
|
A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite 6.2, Satellite 6.1 optional and Satellite Capsule…
|
NVD-CWE-Other
|
CVE-2019-3845
|
2024-11-21 13:42 |
2019-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219825
|
6.1 |
MEDIUM
Local
|
linux redhat
|
linux_kernel enterprise_linux
|
It was found that the net_dma code in tcp_recvmsg() in the 2.6.32 kernel as shipped in RHEL6 is thread-unsafe. So an unprivileged multi-threaded userspace application calling recvmsg() for the same n…
|
CWE-362 CWE-401
Race Condition Missing Release of Memory after Effective Lifetime
|
CVE-2019-3837
|
2024-11-21 13:42 |
2019-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219826
|
7.2 |
HIGH
Network
|
verizon
|
fios_quantum_gateway_g1100_firmware
|
Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a remote, authenticated attacker to execute arbitrary commands on the target device …
|
CWE-78
OS Command
|
CVE-2019-3914
|
2024-11-21 13:42 |
2019-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219827
|
8.1 |
HIGH
Network
|
mikrotik
|
routeros
|
MikroTik RouterOS versions Stable 6.43.12 and below, Long-term 6.42.12 and below, and Testing 6.44beta75 and below are vulnerable to an authenticated, remote directory traversal via the HTTP or Winbo…
|
CWE-22
Path Traversal
|
CVE-2019-3943
|
2024-11-21 13:42 |
2019-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219828
|
7.5 |
HIGH
Adjacent
|
verizon
|
fios_quantum_gateway_g1100_firmware
|
Authentication Bypass by Capture-replay vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an unauthenticated attacker with adjacent network access to intercept…
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2019-3915
|
2024-11-21 13:42 |
2019-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219829
|
4.4 |
MEDIUM
Local
|
mcafee
|
data_exchange_layer threat_intelligence_exchange
|
Information Disclosure vulnerability in McAfee DXL Platform and TIE Server in DXL prior to 5.0.1 HF2 and TIE prior to 2.3.1 HF1 allows Authenticated users to view sensitive information in plain text …
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2019-3612
|
2024-11-21 13:42 |
2019-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219830
|
7.0 |
HIGH
Local
|
systemd_project redhat fedoraproject debian
|
systemd enterprise_linux fedora debian_linux
|
In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular config…
|
CWE-863
Incorrect Authorization
|
CVE-2019-3842
|
2024-11-21 13:42 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|