|
219791
|
9.8 |
CRITICAL
Network
|
facebook
|
hhvm
|
Insufficient boundary checks for the strrpos and strripos functions allow access to out-of-bounds memory. This affects all supported versions of HHVM (4.0.3, 3.30.4, and 3.27.7 and below).
|
CWE-125
Out-of-bounds Read
|
CVE-2019-3561
|
2024-11-21 13:42 |
2019-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219792
|
7.5 |
HIGH
Network
|
facebook
|
fizz
|
An improperly performed length calculation on a buffer in PlaintextRecordLayer could lead to an infinite loop and denial-of-service based on user input. This issue affected versions of fizz prior to …
|
CWE-131 CWE-835
Incorrect Calculation of Buffer Size Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-3560
|
2024-11-21 13:42 |
2019-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219793
|
8.8 |
HIGH
Network
|
microfocus
|
network_operations_management network_automation
|
A potential security vulnerability has been identified in Micro Focus Network Automation Software 9.20, 9.21, 10.00, 10.10, 10.20, 10.30, 10.40, 10.50, 2018.05, 2018.08, 2018.11, and Micro Focus Netw…
|
NVD-CWE-noinfo
|
CVE-2019-3493
|
2024-11-21 13:42 |
2019-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219794
|
7.8 |
HIGH
Local
|
systemd_project canonical netapp
|
systemd ubuntu_linux solidfire hci_management_node snapprotect cn1610_firmware
|
It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by the service transi…
|
-
|
CVE-2019-3844
|
2024-11-21 13:42 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219795
|
7.8 |
HIGH
Local
|
systemd_project fedoraproject canonical netapp
|
systemd fedora ubuntu_linux solidfire hci_management_node snapprotect cn1610_firmware
|
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminate…
|
CWE-269
Improper Privilege Management
|
CVE-2019-3843
|
2024-11-21 13:42 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219796
|
9.8 |
CRITICAL
Network
|
dell
|
idrac9_firmware
|
Dell EMC iDRAC9 versions prior to 3.30.30.30 contain an authentication bypass vulnerability. A remote attacker may potentially exploit this vulnerability to bypass authentication and gain access to t…
|
NVD-CWE-noinfo
|
CVE-2019-3707
|
2024-11-21 13:42 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219797
|
9.8 |
CRITICAL
Network
|
dell
|
idrac9_firmware
|
Dell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22 and 3.21.25.22 contain an authentication bypass vulnerability. A remote attacker may potentially exploit this vulnerability to byp…
|
NVD-CWE-noinfo
|
CVE-2019-3706
|
2024-11-21 13:42 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219798
|
9.8 |
CRITICAL
Network
|
dell
|
idrac7_firmware idrac8_firmware idrac9_firmware idrac6_firmware
|
Dell EMC iDRAC6 versions prior to 2.92, iDRAC7/iDRAC8 versions prior to 2.61.60.60, and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22 and 3.23.23.23 contain a stack-based buffer overflo…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-3705
|
2024-11-21 13:42 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219799
|
9.8 |
CRITICAL
Network
|
cloudfoundry
|
cf-deployment uaa_release credhub
|
Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker coul…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-3801
|
2024-11-21 13:42 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219800
|
6.1 |
MEDIUM
Network
|
cloudfoundry
|
uaa_release
|
Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri. Given a UAA client was configured with a wildcard in the redirect uri's subdomain, a …
|
CWE-601
Open Redirect
|
CVE-2019-3788
|
2024-11-21 13:42 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|