|
221631
|
7.8 |
HIGH
Local
|
linux netapp
|
linux_kernel solidfire_baseboard_management_controller_firmware cloud_backup solidfire_\&_hci_management_node h500s_firmware h700s_firmware h300e_firmware h500e_firmware h…
|
An issue was discovered in the Linux kernel before 5.0.19. The XFRM subsystem has a use-after-free, related to an xfrm_state_fini panic, aka CID-dbb2483b2a46.
|
CWE-416
Use After Free
|
CVE-2019-25045
|
2024-11-21 13:39 |
2021-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221632
|
5.5 |
MEDIUM
Local
|
versa-networks
|
versa_director versa_analytics versa_operating_system
|
In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or key derivation function prior to storage. Popular hashing algorithms based on the…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-25030
|
2024-11-21 13:39 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221633
|
9.8 |
CRITICAL
Network
|
versa-networks
|
versa_director
|
In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are pos…
|
CWE-77
Command Injection
|
CVE-2019-25029
|
2024-11-21 13:39 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221634
|
7.8 |
HIGH
Local
|
linux netapp
|
linux_kernel cloud_backup solidfire_\&_hci_management_node solidfire_baseboard_management_controller_firmware h300s_firmware h500s_firmware h700s_firmware h300e_firmware h…
|
The block subsystem in the Linux kernel before 5.2 has a use-after-free that can lead to arbitrary code execution in the kernel context and privilege escalation, aka CID-c3e2219216c9. This is related…
|
CWE-416
Use After Free
|
CVE-2019-25044
|
2024-11-21 13:39 |
2021-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221635
|
5.3 |
MEDIUM
Network
|
trustwave
|
modsecurity
|
ModSecurity 3.x before 3.0.4 mishandles key-value pair parsing, as demonstrated by a "string index out of range" error and worker-process crash for a "Cookie: =abc" header.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2019-25043
|
2024-11-21 13:39 |
2021-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221636
|
9.8 |
CRITICAL
Network
|
nlnetlabs debian
|
unbound debian_linux
|
Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound …
|
CWE-787
Out-of-bounds Write
|
CVE-2019-25042
|
2024-11-21 13:39 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221637
|
7.5 |
HIGH
Network
|
nlnetlabs debian
|
unbound debian_linux
|
Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unboun…
|
CWE-617
Reachable Assertion
|
CVE-2019-25041
|
2024-11-21 13:39 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221638
|
7.5 |
HIGH
Network
|
nlnetlabs debian
|
unbound debian_linux
|
Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound in…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-25040
|
2024-11-21 13:39 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221639
|
9.8 |
CRITICAL
Network
|
nlnetlabs debian
|
unbound debian_linux
|
Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unboun…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-25039
|
2024-11-21 13:39 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221640
|
9.8 |
CRITICAL
Network
|
nlnetlabs debian
|
unbound debian_linux
|
Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Un…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-25038
|
2024-11-21 13:39 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|