|
219771
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logg…
|
CWE-863
Incorrect Authorization
|
CVE-2019-3848
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219772
|
7.8 |
HIGH
Local
|
openstack redhat
|
ceilometer openstack
|
A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data to log files without DEBUG logging being activated.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-3830
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219773
|
6.1 |
MEDIUM
Network
|
prometheus redhat
|
prometheus openshift_container_platform
|
A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prome…
|
-
|
CVE-2019-3826
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219774
|
7.5 |
HIGH
Network
|
cockpit-project fedoraproject redhat
|
cockpit fedora virtualization
|
It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted re…
|
CWE-909
Missing Initialization of Resource
|
CVE-2019-3804
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219775
|
4.1 |
MEDIUM
Local
|
mcafee
|
network_security_manager
|
Data Leakage Attacks vulnerability in the web portal component when in an MDR pair in McAfee Network Security Management (NSM) 9.1 < 9.1.7.75 (Update 4) and 9.2 < 9.2.7.31 Update2 allows administrato…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2019-3606
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219776
|
9.8 |
CRITICAL
Network
|
mcafee
|
network_security_manager
|
Authentication Bypass vulnerability in McAfee Network Security Manager (NSM) 9.1 < 9.1.7.75.2 and 9.2 < 9.2.7.31 (9.2 Update 2) allows unauthenticated users to gain administrator rights via incorrect…
|
NVD-CWE-noinfo
|
CVE-2019-3597
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219777
|
8.1 |
HIGH
Network
|
ovirt redhat
|
ovirt virtualization
|
It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the permission validation that should be performed against the ca…
|
CWE-862
Missing Authorization
|
CVE-2019-3879
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219778
|
6.5 |
MEDIUM
Adjacent
|
linux debian redhat canonical netapp
|
linux_kernel debian_linux enterprise_linux ubuntu_linux solidfire hci_management_node snapprotect active_iq_unified_manager_for_vmware_vsphere cn1610_firmware
|
The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use this flaw to cause a denial of service attack. Kernel 3.10.x and 4.18.x branches …
|
-
|
CVE-2019-3874
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219779
|
9.1 |
CRITICAL
Network
|
libssh2 debian netapp opensuse
|
libssh2 debian_linux ontap_select_deploy_administration_utility leap
|
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packet length are parsed. A remote attacker who compromises a SSH…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-3861
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219780
|
9.1 |
CRITICAL
Network
|
libssh2 debian netapp opensuse
|
libssh2 debian_linux ontap_select_deploy_administration_utility leap
|
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial …
|
CWE-125
Out-of-bounds Read
|
CVE-2019-3860
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|