Search

Search Results (356062 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-9946 4 Cncf, Kubernetes, Netapp and 1 more 5 Portmap, Kubernetes, Cloud Insights and 2 more 2024-11-21 N/A
Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.
CVE-2019-9945 1 Softnas 1 Cloud 2024-11-21 N/A
SoftNAS Cloud 4.2.0 and 4.2.1 allows remote command execution. The NGINX default configuration file has a check to verify the status of a user cookie. If not set, a user is redirected to the login page. An arbitrary value can be provided for this cookie to access the web interface without valid user credentials. If customers have not followed SoftNAS deployment best practices and expose SoftNAS StorageCenter ports directly to the internet, this vulnerability allows an attacker to gain access to the Webadmin interface to create new users or execute arbitrary commands with administrative privileges, compromising both the platform and the data.
CVE-2019-9944 1 Openmicroscopy 1 Omero.server 2024-11-21 7.5 High
In Open Microscopy Environment OMERO.server 5.0.0 through 5.6.0, the reading of files from imported image filesets may circumvent OMERO permissions restrictions. This occurs because the Bio-Formats feature allows an image file to have embedded pathnames.
CVE-2019-9943 1 Openmicroscopy 1 Omero.server 2024-11-21 7.5 High
In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMERO model objects may be circumvented during certain operations such as move and delete, because group permissions are mishandled.
CVE-2019-9942 2 Debian, Symfony 2 Debian Linux, Twig 2024-11-21 3.7 Low
A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place.
CVE-2019-9939 1 Ushareit 1 Shareit 2024-11-21 N/A
The SHAREit application before 4.0.36 for Android allows a remote attacker (on the same network or joining public "open" Wi-Fi hotspots created by the application when file transfer is initiated) to bypass authentication by trying to fetch a non-existing page. When the non-existing page is requested, the application responds with a 200 status code and empty page, and adds the requesting client device into the list of recognized devices.
CVE-2019-9938 1 Ushareit 1 Shareit 2024-11-21 N/A
The SHAREit application before 4.0.42 for Android allows a remote attacker (on the same network or joining public "open" Wi-Fi hotspots created by the application when file transfer is initiated) to download arbitrary files from the device including contacts, photos, videos, sound clips, etc. The attacker must be authenticated as a "recognized device."
CVE-2019-9937 1 Sqlite 1 Sqlite 2024-11-21 N/A
In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL Pointer Dereference in fts5ChunkIterate in sqlite3.c. This is related to ext/fts5/fts5_hash.c and ext/fts5/fts5_index.c.
CVE-2019-9936 1 Sqlite 1 Sqlite 2024-11-21 N/A
In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlite3.c, which may lead to an information leak. This is related to ext/fts5/fts5_hash.c.
CVE-2019-9935 1 Lexmark 50 Cs31x, Cs31x Firmware, Cs41x and 47 more 2024-11-21 N/A
Various Lexmark products have Incorrect Access Control (issue 2 of 2).
CVE-2019-9934 1 Lexmark 50 Cs31x, Cs31x Firmware, Cs41x and 47 more 2024-11-21 N/A
Various Lexmark products have Incorrect Access Control (issue 1 of 2).
CVE-2019-9933 1 Lexmark 142 6500e, 6500e Firmware, C734 and 139 more 2024-11-21 N/A
Various Lexmark products have a Buffer Overflow (issue 3 of 3).
CVE-2019-9932 1 Lexmark 142 6500e, 6500e Firmware, C734 and 139 more 2024-11-21 N/A
Various Lexmark products have a Buffer Overflow (issue 2 of 3).
CVE-2019-9931 1 Lexmark 142 6500e, 6500e Firmware, C734 and 139 more 2024-11-21 N/A
Various Lexmark printers contain a denial of service vulnerability in the SNMP service that can be exploited to crash the device.
CVE-2019-9930 1 Lexmark 142 6500e, 6500e Firmware, C734 and 139 more 2024-11-21 N/A
Various Lexmark products have an Integer Overflow.
CVE-2019-9929 1 Northern 1 Cfengine 2024-11-21 N/A
Northern.tech CFEngine Enterprise 3.12.1 has Insecure Permissions.
CVE-2019-9927 1 Caret 1 Caret 2024-11-21 N/A
Caret before 2019-02-22 allows Remote Code Execution.
CVE-2019-9926 1 Labkey 1 Labkey Server 2024-11-21 8.8 High
An issue was discovered in LabKey Server 19.1.0. It is possible to force a logged-in administrator to execute code through a /reports-viewScriptReport.view CSRF vulnerability.
CVE-2019-9925 1 S-cms 1 S-cms 2024-11-21 N/A
S-CMS PHP v1.0 has XSS in 4.edu.php via the S_id parameter.
CVE-2019-9924 6 Canonical, Debian, Gnu and 3 more 12 Ubuntu Linux, Debian Linux, Bash and 9 more 2024-11-21 7.8 High
rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.