|
220251
|
7.0 |
HIGH
Local
|
gnome
|
gvfs
|
An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users without asking for password when no authe…
|
CWE-863
Incorrect Authorization
|
CVE-2019-3827
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220252
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included a…
|
CWE-79
Cross-site Scripting
|
CVE-2019-3810
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220253
|
10.0 |
CRITICAL
Network
|
moodle
|
moodle
|
A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Ba…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-3809
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220254
|
5.4 |
MEDIUM
Network
|
moodle
|
moodle
|
A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned …
|
CWE-79
Cross-site Scripting
|
CVE-2019-3808
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220255
|
7.8 |
HIGH
Local
|
hp
|
arcsight_logger
|
Mitigates a remote code execution issue in ArcSight Logger versions prior to 6.7.
|
NVD-CWE-noinfo
|
CVE-2019-3484
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220256
|
6.5 |
MEDIUM
Network
|
hp
|
arcsight_logger
|
Mitigates a potential information leakage issue in ArcSight Logger versions prior to 6.7.
|
NVD-CWE-noinfo
|
CVE-2019-3483
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220257
|
6.5 |
MEDIUM
Network
|
hp
|
arcsight_logger
|
Mitigates a directory traversal issue in ArcSight Logger versions prior to 6.7.
|
CWE-22
Path Traversal
|
CVE-2019-3482
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220258
|
7.1 |
HIGH
Network
|
hp
|
arcsight_logger
|
Mitigates a XML External Entity Parsing issue in ArcSight Logger versions prior to 6.7.
|
CWE-611
XXE
|
CVE-2019-3481
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220259
|
6.1 |
MEDIUM
Network
|
hp
|
arcsight_logger
|
Mitigates a stored/reflected XSS issue in ArcSight Logger versions prior to 6.7.
|
CWE-79
Cross-site Scripting
|
CVE-2019-3480
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220260
|
9.8 |
CRITICAL
Network
|
hp
|
arcsight_logger
|
Mitigates a potential remote code execution issue in ArcSight Logger versions prior to 6.7.
|
NVD-CWE-noinfo
|
CVE-2019-3479
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|