|
222391
|
7.8 |
HIGH
Local
|
cisco
|
nx-os
|
A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege level to root. The attacker must authenticate with v…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-1596
|
2024-11-21 13:36 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222392
|
6.5 |
MEDIUM
Adjacent
|
cisco
|
nx-os
|
A vulnerability in the Fibre Channel over Ethernet (FCoE) protocol implementation in Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) conditio…
|
CWE-913
Improper Control of Dynamically-Managed Code Resources
|
CVE-2019-1595
|
2024-11-21 13:36 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222393
|
7.4 |
HIGH
Adjacent
|
cisco
|
nx-os
|
A vulnerability in the 802.1X implementation for Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnera…
|
CWE-20
Improper Input Validation
|
CVE-2019-1594
|
2024-11-21 13:36 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222394
|
7.8 |
HIGH
Local
|
cisco
|
nx-os
|
A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege level by executing commands authorized to other user…
|
NVD-CWE-noinfo
|
CVE-2019-1593
|
2024-11-21 13:36 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222395
|
7.8 |
HIGH
Local
|
cisco
|
nx-os
|
A vulnerability in a specific CLI command implementation of Cisco Nexus 9000 Series ACI Mode Switch Software could allow an authenticated, local attacker to escape a restricted shell on an affected d…
|
CWE-78
OS Command
|
CVE-2019-1591
|
2024-11-21 13:36 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222396
|
4.4 |
MEDIUM
Local
|
cisco
|
nx-os
|
A vulnerability in the Cisco Nexus 9000 Series Fabric Switches running in Application-Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an affe…
|
CWE-269
Improper Privilege Management
|
CVE-2019-1588
|
2024-11-21 13:36 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222397
|
7.8 |
HIGH
Local
|
cisco
|
nx-os application_policy_infrastructure_controller_software
|
A vulnerability in the controller authorization functionality of Cisco Nexus 9000 Series ACI Mode Switch Software could allow an authenticated, local attacker to escalate standard users with root pri…
|
CWE-16
Configuration
|
CVE-2019-1585
|
2024-11-21 13:36 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222398
|
7.4 |
HIGH
Network
|
openssl
|
openssl
|
ChaCha20-Poly1305 is an AEAD cipher, and requires a unique nonce input for every encryption operation. RFC 7539 specifies that the nonce value (IV) should be 96 bits (12 bytes). OpenSSL allows a vari…
|
CWE-327 CWE-330
Use of a Broken or Risky Cryptographic Algorithm Use of Insufficiently Random Values
|
CVE-2019-1543
|
2024-11-21 13:36 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222399
|
5.9 |
MEDIUM
Network
|
openssl canonical debian netapp f5 tenable opensuse fedoraproject mcafee redhat oracle paloaltonetworks nodejs
|
openssl ubuntu_linux debian_linux hyper_converged_infrastructure cloud_backup santricity_smi-s_provider element_software snapdrive snapcenter storage_automation_store on…
|
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling appl…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-1559
|
2024-11-21 13:36 |
2019-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222400
|
6.1 |
MEDIUM
Network
|
paloaltonetworks
|
pan-os
|
The PAN-OS management web interface in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an unauthenticated attacker to inject arbitrary JavaScript or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2019-1566
|
2024-11-21 13:36 |
2019-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|