|
219801
|
7.5 |
HIGH
Network
|
dell
|
emc_openmanage_server_administrator
|
Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain an Improper Range Header Processing Vulnerability. A remote unauthenticated attacker may send crafted requests with ov…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-3721
|
2024-11-21 13:42 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219802
|
4.9 |
MEDIUM
Network
|
dell
|
emc_openmanage_server_administrator
|
Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain a Directory Traversal Vulnerability. A remote authenticated malicious user with admin privileges could potentially exp…
|
CWE-22
Path Traversal
|
CVE-2019-3720
|
2024-11-21 13:42 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219803
|
7.7 |
HIGH
Network
|
linux fedoraproject redhat debian canonical netapp oracle
|
linux_kernel fedora enterprise_linux debian_linux ubuntu_linux vasa_provider_for_clustered_data_ontap solidfire hci_management_node snapprotect active_iq_unified_manager_fo…
|
An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets f…
|
-
|
CVE-2019-3900
|
2024-11-21 13:42 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219804
|
5.5 |
MEDIUM
Local
|
linux fedoraproject debian canonical opensuse netapp
|
linux_kernel fedora debian_linux ubuntu_linux leap vasa_provider_for_clustered_data_ontap solidfire hci_management_node snapprotect active_iq_unified_manager_for_vmware_vsp…
|
A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local a…
|
-
|
CVE-2019-3882
|
2024-11-21 13:42 |
2019-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219805
|
3.8 |
LOW
Network
|
redhat
|
keycloak
|
Keycloak up to version 6.0.0 allows the end user token (access or id token JWT) to be used as the session cookie for browser sessions for OIDC. As a result an attacker with access to service provider…
|
CWE-200
Information Exposure
|
CVE-2019-3868
|
2024-11-21 13:42 |
2019-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219806
|
9.8 |
CRITICAL
Network
|
pivotal_software
|
application_service
|
Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21, versions 667.0.x prior to 667.0.7, contain an invitation service that accepts HTTP. A remote unau…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-3793
|
2024-11-21 13:42 |
2019-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219807
|
6.5 |
MEDIUM
Network
|
cloudfoundry
|
routing_release
|
Cloud Foundry Routing Release, all versions prior to 0.188.0, contains a vulnerability that can hijack the traffic to route services hosted outside the platform. A user with space developer permissio…
|
CWE-269
Improper Privilege Management
|
CVE-2019-3789
|
2024-11-21 13:42 |
2019-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219808
|
7.1 |
HIGH
Network
|
cloudfoundry
|
bosh_backup_and_restore
|
Cloud Foundry BOSH Backup and Restore CLI, all versions prior to 1.5.0, does not check the authenticity of backup scripts in BOSH. A remote authenticated malicious user can modify the metadata file o…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-3786
|
2024-11-21 13:42 |
2019-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219809
|
5.9 |
MEDIUM
Network
|
mercurial redhat debian
|
mercurial enterprise_linux debian_linux
|
A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.
|
CWE-59
Link Following
|
CVE-2019-3902
|
2024-11-21 13:42 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219810
|
9.8 |
CRITICAL
Network
|
redhat heketi_project
|
openshift_container_platform heketi
|
It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift …
|
-
|
CVE-2019-3899
|
2024-11-21 13:42 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|