|
219831
|
7.5 |
HIGH
Network
|
advantech
|
webaccess
|
Advantech WebAccess 8.3.4 allows unauthenticated, remote attackers to delete arbitrary files via IOCTL 10005 RPC.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-3941
|
2024-11-21 13:42 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219832
|
9.8 |
CRITICAL
Network
|
advantech
|
webaccess
|
Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unauthenticated, remote attacker can use this vulnerability to execute arbitrary code.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-3940
|
2024-11-21 13:42 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219833
|
4.9 |
MEDIUM
Network
|
theforeman redhat
|
foreman satellite
|
In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to the disclosure of the plaintext password or token for the affected compute resour…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-3893
|
2024-11-21 13:42 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219834
|
5.4 |
MEDIUM
Network
|
samba debian redhat fedoraproject opensuse
|
samba debian_linux enterprise_linux gluster_storage fedora leap
|
A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they…
|
CWE-22
Path Traversal
|
CVE-2019-3880
|
2024-11-21 13:42 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219835
|
5.6 |
MEDIUM
Local
|
linux fedoraproject canonical redhat
|
linux_kernel fedora ubuntu_linux enterprise_linux enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus enterprise_linux_for_real_time enterprise_linux_…
|
A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtualization enabled. In that, L1 guest could access L0's APIC register values via …
|
-
|
CVE-2019-3887
|
2024-11-21 13:42 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219836
|
6.1 |
MEDIUM
Local
|
samba fedoraproject synology
|
samba fedora diskstation_manager directory_server router_manager skynas_firmware vs960hd_firmware
|
A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the insta…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-3870
|
2024-11-21 13:42 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219837
|
5.3 |
MEDIUM
Network
|
vmware debian
|
spring_security debian_linux
|
Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a …
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2019-3795
|
2024-11-21 13:42 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219838
|
5.4 |
MEDIUM
Adjacent
|
redhat opensuse fedoraproject
|
libvirt leap fedora
|
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing u…
|
-
|
CVE-2019-3886
|
2024-11-21 13:42 |
2019-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219839
|
7.5 |
HIGH
Network
|
pivotal_software
|
concourse
|
Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a version identifier that can carry a SQL injection payload to the Concourse serv…
|
CWE-89
SQL Injection
|
CVE-2019-3792
|
2024-11-21 13:42 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219840
|
7.5 |
HIGH
Network
|
microfocus
|
content_manager
|
An unauthenticated file upload vulnerability has been identified in the Web Client component of Micro Focus Content Manager 9.1, 9.2, and 9.3 when configured to use the ADFS authentication method. Th…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-3489
|
2024-11-21 13:42 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|