|
218991
|
4.1 |
MEDIUM
Physics
|
redhat
|
quay
|
A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or delete a user's con…
|
-
|
CVE-2019-3867
|
2024-11-21 13:42 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218992
|
5.3 |
MEDIUM
Network
|
redhat
|
certification
|
It has been discovered in redhat-certification that any unauthorized user may download any file under /var/www/rhcert, provided they know its name. Red Hat Certification 6 and 7 is vulnerable to this…
|
-
|
CVE-2019-3897
|
2024-11-21 13:42 |
2021-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218993
|
5.3 |
MEDIUM
Network
|
360
|
360f5_firmware
|
In the 3.1.3.64296 and lower version of 360F5, the third party can trigger the device to send a deauth frame by constructing and sending a specific illegal 802.11 Null Data Frame, which will cause ot…
|
NVD-CWE-noinfo
|
CVE-2019-3405
|
2024-11-21 13:42 |
2021-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218994
|
7.8 |
HIGH
Local
|
bundler
|
bundler
|
Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler i…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-3881
|
2024-11-21 13:42 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218995
|
9.8 |
CRITICAL
Network
|
opensuse
|
osc
|
A External Control of File Name or Path vulnerability in osc of SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Software Development Kit 12-SP5, SUSE Linux Enterprise Sof…
|
-
|
CVE-2019-3681
|
2024-11-21 13:42 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218996
|
6.1 |
MEDIUM
Network
|
redhat
|
quay
|
A vulnerability was found in quay-2, where a stored XSS vulnerability has been found in the super user function of quay. Attackers are able to use the name field of service key to inject scripts and …
|
CWE-79
Cross-site Scripting
|
CVE-2019-3865
|
2024-11-21 13:42 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218997
|
6.8 |
MEDIUM
Physics
|
mcafee
|
virusscan_enterprise
|
Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow unauthorized users to interact with the On-Access Scan…
|
CWE-269
Improper Privilege Management
|
CVE-2019-3588
|
2024-11-21 13:42 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218998
|
7.8 |
HIGH
Local
|
mcafee
|
virusscan_enterprise
|
Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow local users to interact with the On-Access Scan Messag…
|
CWE-269
Improper Privilege Management
|
CVE-2019-3585
|
2024-11-21 13:42 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218999
|
7.3 |
HIGH
Local
|
mcafee
|
agent
|
DLL Search Order Hijacking vulnerability in McAfee Agent (MA) prior to 5.6.4 allows attackers with local access to execute arbitrary code via execution from a compromised folder.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-3613
|
2024-11-21 13:42 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219000
|
8.2 |
HIGH
Local
|
mcafee
|
total_protection
|
Privilege escalation vulnerability in McAfee Total Protection (ToPS) for Mac OS prior to 4.6 allows local users to gain root privileges via incorrect protection of temporary files.
|
CWE-269
Improper Privilege Management
|
CVE-2019-3617
|
2024-11-21 13:42 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|