|
219931
|
7.8 |
HIGH
Local
|
dell
|
emc_vnx2_firmware
|
VNX Control Station in Dell EMC VNX2 OE for File versions prior to 8.1.9.236 contains OS command injection vulnerability. Due to inadequate restriction configured in sudores, a local authenticated ma…
|
CWE-78
OS Command
|
CVE-2019-3704
|
2024-11-21 13:42 |
2019-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219932
|
6.4 |
MEDIUM
Physics
|
gnome canonical redhat
|
gnome_display_manager ubuntu_linux enterprise_linux
|
A vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could bypass the lock screen by selecting the timed login user and waiting for the timer…
|
CWE-287
Improper Authentication
|
CVE-2019-3825
|
2024-11-21 13:42 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219933
|
4.3 |
MEDIUM
Physics
|
gnome opensuse canonical
|
gnome-shell leap ubuntu_linux
|
It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An attacker with physical access to a locked workstation could invoke certai…
|
CWE-287
Improper Authentication
|
CVE-2019-3820
|
2024-11-21 13:42 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219934
|
9.8 |
CRITICAL
Network
|
pizzashack debian fedoraproject canonical
|
rssh debian_linux fedora ubuntu_linux
|
Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulti…
|
CWE-665
Improper Initialization
|
CVE-2019-3464
|
2024-11-21 13:42 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219935
|
9.8 |
CRITICAL
Network
|
pizzashack debian fedoraproject canonical
|
rssh debian_linux fedora ubuntu_linux
|
Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the ex…
|
CWE-88
Argument Injection
|
CVE-2019-3463
|
2024-11-21 13:42 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219936
|
7.5 |
HIGH
Network
|
haxx canonical debian netapp oracle
|
libcurl ubuntu_linux debian_linux clustered_data_ontap http_server secure_global_desktop communications_operations_monitor
|
libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL termi…
|
-
|
CVE-2019-3823
|
2024-11-21 13:42 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219937
|
9.8 |
CRITICAL
Network
|
haxx canonical debian netapp siemens oracle redhat
|
libcurl ubuntu_linux debian_linux snapcenter oncommand_workflow_automation oncommand_insight active_iq_unified_manager clustered_data_ontap sinema_remote_connect_client htt…
|
libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_mess…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-3822
|
2024-11-21 13:42 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219938
|
7.5 |
HIGH
Network
|
redhat kube-rbac-proxy_project
|
openshift_container_platform kube-rbac-proxy
|
The kube-rbac-proxy container before version 0.4.1 as used in Red Hat OpenShift Container Platform does not honor TLS configurations, allowing for use of insecure ciphers and TLS 1.0. An attacker cou…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-3818
|
2024-11-21 13:42 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219939
|
7.0 |
HIGH
Local
|
debian
|
tmpreaper debian_linux
|
Debian tmpreaper version 1.6.13+nmu1 has a race condition when doing a (bind) mount via rename() which could result in local privilege escalation. Mounting via rename() could potentially lead to a fi…
|
CWE-362
Race Condition
|
CVE-2019-3461
|
2024-11-21 13:42 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219940
|
7.5 |
HIGH
Adjacent
|
spice_project redhat debian canonical
|
spice enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_eus enterprise_linux_server_aus debian_lin…
|
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-executi…
|
CWE-193
Off-by-one Error
|
CVE-2019-3813
|
2024-11-21 13:42 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|