|
222771
|
6.1 |
MEDIUM
Network
|
prometheus redhat
|
prometheus openshift_container_platform
|
A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prome…
|
-
|
CVE-2019-3826
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222772
|
7.5 |
HIGH
Network
|
cockpit-project fedoraproject redhat
|
cockpit fedora virtualization
|
It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted re…
|
CWE-909
Missing Initialization of Resource
|
CVE-2019-3804
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222773
|
4.1 |
MEDIUM
Local
|
mcafee
|
network_security_manager
|
Data Leakage Attacks vulnerability in the web portal component when in an MDR pair in McAfee Network Security Management (NSM) 9.1 < 9.1.7.75 (Update 4) and 9.2 < 9.2.7.31 Update2 allows administrato…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2019-3606
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222774
|
9.8 |
CRITICAL
Network
|
mcafee
|
network_security_manager
|
Authentication Bypass vulnerability in McAfee Network Security Manager (NSM) 9.1 < 9.1.7.75.2 and 9.2 < 9.2.7.31 (9.2 Update 2) allows unauthenticated users to gain administrator rights via incorrect…
|
NVD-CWE-noinfo
|
CVE-2019-3597
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222775
|
8.1 |
HIGH
Network
|
ovirt redhat
|
ovirt virtualization
|
It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the permission validation that should be performed against the ca…
|
CWE-862
Missing Authorization
|
CVE-2019-3879
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222776
|
6.5 |
MEDIUM
Adjacent
|
linux debian redhat canonical netapp
|
linux_kernel debian_linux enterprise_linux ubuntu_linux solidfire hci_management_node snapprotect active_iq_unified_manager_for_vmware_vsphere cn1610_firmware
|
The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use this flaw to cause a denial of service attack. Kernel 3.10.x and 4.18.x branches …
|
-
|
CVE-2019-3874
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222777
|
9.1 |
CRITICAL
Network
|
libssh2 debian netapp opensuse
|
libssh2 debian_linux ontap_select_deploy_administration_utility leap
|
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packet length are parsed. A remote attacker who compromises a SSH…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-3861
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222778
|
9.1 |
CRITICAL
Network
|
libssh2 debian netapp opensuse
|
libssh2 debian_linux ontap_select_deploy_administration_utility leap
|
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial …
|
CWE-125
Out-of-bounds Read
|
CVE-2019-3860
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222779
|
8.8 |
HIGH
Network
|
libssh2 debian netapp opensuse redhat fedoraproject oracle
|
libssh2 debian_linux ontap_select_deploy_administration_utility leap enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus …
|
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit signal are parsed. A remote attacker…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2019-3857
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222780
|
8.8 |
HIGH
Network
|
libssh2 debian netapp opensuse redhat fedoraproject oracle
|
libssh2 debian_linux ontap_select_deploy_administration_utility leap enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus …
|
An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are parsed. A remote attacker who compromises a SSH se…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2019-3856
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|