|
223151
|
7.8 |
HIGH
Local
|
cisco
|
nx-os
|
A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege level by executing commands authorized to other user…
|
NVD-CWE-noinfo
|
CVE-2019-1593
|
2024-11-21 13:36 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223152
|
7.8 |
HIGH
Local
|
cisco
|
nx-os
|
A vulnerability in a specific CLI command implementation of Cisco Nexus 9000 Series ACI Mode Switch Software could allow an authenticated, local attacker to escape a restricted shell on an affected d…
|
CWE-78
OS Command
|
CVE-2019-1591
|
2024-11-21 13:36 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223153
|
4.4 |
MEDIUM
Local
|
cisco
|
nx-os
|
A vulnerability in the Cisco Nexus 9000 Series Fabric Switches running in Application-Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an affe…
|
CWE-269
Improper Privilege Management
|
CVE-2019-1588
|
2024-11-21 13:36 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223154
|
7.8 |
HIGH
Local
|
cisco
|
nx-os application_policy_infrastructure_controller_software
|
A vulnerability in the controller authorization functionality of Cisco Nexus 9000 Series ACI Mode Switch Software could allow an authenticated, local attacker to escalate standard users with root pri…
|
CWE-16
Configuration
|
CVE-2019-1585
|
2024-11-21 13:36 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223155
|
7.4 |
HIGH
Network
|
openssl
|
openssl
|
ChaCha20-Poly1305 is an AEAD cipher, and requires a unique nonce input for every encryption operation. RFC 7539 specifies that the nonce value (IV) should be 96 bits (12 bytes). OpenSSL allows a vari…
|
CWE-327 CWE-330
Use of a Broken or Risky Cryptographic Algorithm Use of Insufficiently Random Values
|
CVE-2019-1543
|
2024-11-21 13:36 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223156
|
5.9 |
MEDIUM
Network
|
openssl canonical debian netapp f5 tenable opensuse fedoraproject mcafee redhat oracle paloaltonetworks nodejs
|
openssl ubuntu_linux debian_linux hyper_converged_infrastructure cloud_backup santricity_smi-s_provider element_software snapdrive snapcenter storage_automation_store on…
|
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling appl…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-1559
|
2024-11-21 13:36 |
2019-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223157
|
6.1 |
MEDIUM
Network
|
paloaltonetworks
|
pan-os
|
The PAN-OS management web interface in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an unauthenticated attacker to inject arbitrary JavaScript or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2019-1566
|
2024-11-21 13:36 |
2019-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223158
|
5.4 |
MEDIUM
Network
|
paloaltonetworks
|
pan-os
|
The PAN-OS external dynamics lists in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an attacker that is authenticated in Next Generation Firewall with …
|
CWE-79
Cross-site Scripting
|
CVE-2019-1565
|
2024-11-21 13:36 |
2019-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223159
|
7.5 |
HIGH
Network
|
cisco
|
iot_field_network_director
|
A vulnerability in the UDP protocol implementation for Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker to exhaust system resources, resulting in a denial of…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-1644
|
2024-11-21 13:36 |
2019-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223160
|
6.1 |
MEDIUM
Network
|
cisco
|
prime_infrastructure
|
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of th…
|
CWE-79
Cross-site Scripting
|
CVE-2019-1643
|
2024-11-21 13:36 |
2019-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|