|
219851
|
8.8 |
HIGH
Network
|
rpm
|
libcomps
|
A use-after-free flaw has been discovered in libcomps before version 0.1.10 in the way ObjMRTrees are merged. An attacker, who is able to make an application read a crafted comps XML file, may be abl…
|
CWE-416
Use After Free
|
CVE-2019-3817
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219852
|
6.8 |
MEDIUM
Network
|
dovecot canonical opensuse
|
dovecot ubuntu_linux leap
|
It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could …
|
CWE-295
Improper Certificate Validation
|
CVE-2019-3814
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219853
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
A vulnerability was found in moodle before version 3.6.3. The get_with_capability_join and get_users_by_capability functions were not taking context freezing into account when checking user capabilit…
|
NVD-CWE-noinfo
|
CVE-2019-3852
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219854
|
4.3 |
MEDIUM
Network
|
moodle fedoraproject
|
moodle fedora
|
A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page.
|
NVD-CWE-noinfo
|
CVE-2019-3851
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219855
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may…
|
CWE-601
Open Redirect
|
CVE-2019-3850
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219856
|
8.1 |
HIGH
Network
|
mod_auth_mellon_project fedoraproject redhat canonical
|
mod_auth_mellon fedora enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_eus e…
|
A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through authenticated users (with the require val…
|
CWE-287
Improper Authentication
|
CVE-2019-3878
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219857
|
8.8 |
HIGH
Network
|
moodle
|
moodle
|
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the…
|
CWE-269
Improper Privilege Management
|
CVE-2019-3849
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219858
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logg…
|
CWE-863
Incorrect Authorization
|
CVE-2019-3848
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219859
|
7.8 |
HIGH
Local
|
openstack redhat
|
ceilometer openstack
|
A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data to log files without DEBUG logging being activated.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-3830
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219860
|
6.1 |
MEDIUM
Network
|
prometheus redhat
|
prometheus openshift_container_platform
|
A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prome…
|
-
|
CVE-2019-3826
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|