|
219941
|
8.8 |
HIGH
Network
|
mcafee
|
epolicy_orchestrator
|
Cross-Site Request Forgery (CSRF) vulnerability in McAfee ePO (legacy) Cloud allows unauthenticated users to perform unintended ePO actions using an authenticated user's session via unspecified vecto…
|
CWE-352
Origin Validation Error
|
CVE-2019-3604
|
2024-11-21 13:42 |
2019-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219942
|
4.9 |
MEDIUM
Network
|
labkey
|
labkey_server
|
Command manipulation in LabKey Server Community Edition before 18.3.0-61806.763 allows an authenticated remote attacker to unmount any drive on the system leading to denial of service.
|
CWE-78
OS Command
|
CVE-2019-3913
|
2024-11-21 13:42 |
2019-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219943
|
6.1 |
MEDIUM
Network
|
labkey
|
labkey_server
|
An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL parameter allows an unauthenticated remote attacker to redirect users to arbitrary w…
|
CWE-601
Open Redirect
|
CVE-2019-3912
|
2024-11-21 13:42 |
2019-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219944
|
6.1 |
MEDIUM
Network
|
labkey
|
labkey_server
|
Reflected cross-site scripting (XSS) vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 allows an unauthenticated remote attacker to inject arbitrary javascript via the onerror …
|
CWE-79
Cross-site Scripting
|
CVE-2019-3911
|
2024-11-21 13:42 |
2019-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219945
|
9.8 |
CRITICAL
Network
|
powerdns
|
recursor
|
An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authoritative servers with the AA flag not set were not properl…
|
CWE-295
Improper Certificate Validation
|
CVE-2019-3807
|
2024-11-21 13:42 |
2019-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219946
|
8.1 |
HIGH
Network
|
powerdns
|
recursor
|
An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly…
|
NVD-CWE-noinfo
|
CVE-2019-3806
|
2024-11-21 13:42 |
2019-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219947
|
8.1 |
HIGH
Network
|
debian canonical netapp
|
advanced_package_tool ubuntu_linux debian_linux element_software active_iq
|
Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code executio…
|
NVD-CWE-noinfo
|
CVE-2019-3462
|
2024-11-21 13:42 |
2019-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219948
|
7.1 |
HIGH
Local
|
mcafee
|
total_protection
|
Exploitation of Privilege/Trust vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0.R18 allows local users to bypass product self-protection, tamper with policies…
|
NVD-CWE-noinfo
|
CVE-2019-3593
|
2024-11-21 13:42 |
2019-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219949
|
3.3 |
LOW
Local
|
redhat debian
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_eus enterprise_linux_server_aus openshift_container_platform debian_linux
|
A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c does not free the memory allocated by set_i…
|
-
|
CVE-2019-3815
|
2024-11-21 13:42 |
2019-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219950
|
4.4 |
MEDIUM
Local
|
linux debian canonical opensuse
|
linux_kernel debian_linux ubuntu_linux leap
|
A flaw was found in the Linux kernel in the function hid_debug_events_read() in drivers/hid/hid-debug.c file which may enter an infinite loop with certain parameters passed from a userspace. A local …
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-3819
|
2024-11-21 13:42 |
2019-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|