|
222721
|
9.8 |
CRITICAL
Network
|
redhat heketi_project
|
openshift_container_platform heketi
|
It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift …
|
-
|
CVE-2019-3899
|
2024-11-21 13:42 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222722
|
4.7 |
MEDIUM
Local
|
linux debian netapp
|
linux_kernel debian_linux vasa_provider_for_clustered_data_ontap solidfire hci_management_node snapprotect active_iq_unified_manager_for_vmware_vsphere virtual_storage_console_fo…
|
A race condition in perf_event_open() allows local attackers to leak sensitive data from setuid programs. As no relevant locks (in particular the cred_guard_mutex) are held during the ptrace_may_acce…
|
-
|
CVE-2019-3901
|
2024-11-21 13:42 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222723
|
8.0 |
HIGH
Adjacent
|
dell
|
supportassist
|
Dell SupportAssist Client versions prior to 3.2.0.90 contain a remote code execution vulnerability. An unauthenticated attacker, sharing the network access layer with the vulnerable system, can compr…
|
NVD-CWE-noinfo
|
CVE-2019-3719
|
2024-11-21 13:42 |
2019-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222724
|
8.8 |
HIGH
Network
|
dell
|
supportassist
|
Dell SupportAssist Client versions prior to 3.2.0.90 contain an improper origin validation vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to attempt CS…
|
CWE-352
Origin Validation Error
|
CVE-2019-3718
|
2024-11-21 13:42 |
2019-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222725
|
7.5 |
HIGH
Network
|
clusterlabs canonical fedoraproject
|
pacemaker ubuntu_linux fedora
|
A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in certain sensitive information to be leaked via the system logs.
|
CWE-416
Use After Free
|
CVE-2019-3885
|
2024-11-21 13:42 |
2019-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222726
|
8.8 |
HIGH
Network
|
atlassian
|
confluence confluence_server
|
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to crea…
|
CWE-22
Path Traversal
|
CVE-2019-3398
|
2024-11-21 13:42 |
2019-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222727
|
7.5 |
HIGH
Network
|
cloudfoundry
|
capi-release
|
Cloud Foundry Cloud Controller API Release, versions prior to 1.79.0, contains improper authentication when validating user permissions. A remote authenticated malicious user with the ability to crea…
|
CWE-287
Improper Authentication
|
CVE-2019-3798
|
2024-11-21 13:42 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222728
|
9.6 |
CRITICAL
Network
|
dell
|
emc_isilonsd_management_server
|
IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while registering vCenter servers. A remote attacker can trick an admin user to potentially exploit this vulnerability t…
|
CWE-79
Cross-site Scripting
|
CVE-2019-3709
|
2024-11-21 13:42 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222729
|
9.6 |
CRITICAL
Network
|
dell
|
emc_isilonsd_management_server
|
IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while uploading an OVA file. A remote attacker can trick an admin user to potentially exploit this vulnerability to exec…
|
CWE-79
Cross-site Scripting
|
CVE-2019-3708
|
2024-11-21 13:42 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222730
|
7.5 |
HIGH
Network
|
fedoraproject debian redhat
|
389_directory_server debian_linux enterprise_linux
|
In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2019-3883
|
2024-11-21 13:42 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|