|
219851
|
7.5 |
HIGH
Network
|
redhat kube-rbac-proxy_project
|
openshift_container_platform kube-rbac-proxy
|
The kube-rbac-proxy container before version 0.4.1 as used in Red Hat OpenShift Container Platform does not honor TLS configurations, allowing for use of insecure ciphers and TLS 1.0. An attacker cou…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-3818
|
2024-11-21 13:42 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219852
|
7.0 |
HIGH
Local
|
debian
|
tmpreaper debian_linux
|
Debian tmpreaper version 1.6.13+nmu1 has a race condition when doing a (bind) mount via rename() which could result in local privilege escalation. Mounting via rename() could potentially lead to a fi…
|
CWE-362
Race Condition
|
CVE-2019-3461
|
2024-11-21 13:42 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219853
|
7.5 |
HIGH
Adjacent
|
spice_project redhat debian canonical
|
spice enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_eus enterprise_linux_server_aus debian_lin…
|
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-executi…
|
CWE-193
Off-by-one Error
|
CVE-2019-3813
|
2024-11-21 13:42 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219854
|
8.8 |
HIGH
Network
|
mcafee
|
epolicy_orchestrator
|
Cross-Site Request Forgery (CSRF) vulnerability in McAfee ePO (legacy) Cloud allows unauthenticated users to perform unintended ePO actions using an authenticated user's session via unspecified vecto…
|
CWE-352
Origin Validation Error
|
CVE-2019-3604
|
2024-11-21 13:42 |
2019-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219855
|
4.9 |
MEDIUM
Network
|
labkey
|
labkey_server
|
Command manipulation in LabKey Server Community Edition before 18.3.0-61806.763 allows an authenticated remote attacker to unmount any drive on the system leading to denial of service.
|
CWE-78
OS Command
|
CVE-2019-3913
|
2024-11-21 13:42 |
2019-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219856
|
6.1 |
MEDIUM
Network
|
labkey
|
labkey_server
|
An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL parameter allows an unauthenticated remote attacker to redirect users to arbitrary w…
|
CWE-601
Open Redirect
|
CVE-2019-3912
|
2024-11-21 13:42 |
2019-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219857
|
6.1 |
MEDIUM
Network
|
labkey
|
labkey_server
|
Reflected cross-site scripting (XSS) vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 allows an unauthenticated remote attacker to inject arbitrary javascript via the onerror …
|
CWE-79
Cross-site Scripting
|
CVE-2019-3911
|
2024-11-21 13:42 |
2019-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219858
|
9.8 |
CRITICAL
Network
|
powerdns
|
recursor
|
An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authoritative servers with the AA flag not set were not properl…
|
CWE-295
Improper Certificate Validation
|
CVE-2019-3807
|
2024-11-21 13:42 |
2019-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219859
|
8.1 |
HIGH
Network
|
powerdns
|
recursor
|
An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly…
|
NVD-CWE-noinfo
|
CVE-2019-3806
|
2024-11-21 13:42 |
2019-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219860
|
8.1 |
HIGH
Network
|
debian canonical netapp
|
advanced_package_tool ubuntu_linux debian_linux element_software active_iq
|
Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code executio…
|
NVD-CWE-noinfo
|
CVE-2019-3462
|
2024-11-21 13:42 |
2019-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|