Show filters
203 Total Results
Displaying 131-140 of 203
Sort by:
Attacker Value
Unknown

CVE-2019-10195

Disclosure Date: November 27, 2019 (last updated November 08, 2023)
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed.
Attacker Value
Unknown

CVE-2012-5631

Disclosure Date: November 25, 2019 (last updated November 27, 2024)
ipa 3.0 does not properly check server identity before sending credential containing cookies
Attacker Value
Unknown

CVE-2019-18635

Disclosure Date: October 30, 2019 (last updated November 27, 2024)
An issue was discovered in Mooltipass Moolticute through v0.42.1 and v0.42.x-testing through v0.42.5-testing. There is a NULL pointer dereference in MPDevice_win.cpp.
Attacker Value
Unknown

CVE-2019-12967

Disclosure Date: October 22, 2019 (last updated November 27, 2024)
Stephan Mooltipass Moolticute through 0.42.1 (and possibly earlier versions) has Incorrect Access Control.
Attacker Value
Unknown

CVE-2019-16693

Disclosure Date: September 22, 2019 (last updated November 27, 2024)
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.
Attacker Value
Unknown

CVE-2019-16695

Disclosure Date: September 22, 2019 (last updated November 27, 2024)
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used.
Attacker Value
Unknown

CVE-2019-16694

Disclosure Date: September 22, 2019 (last updated November 27, 2024)
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit-result.php table parameter when action=add is used.
Attacker Value
Unknown

CVE-2019-16696

Disclosure Date: September 22, 2019 (last updated November 27, 2024)
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used.
Attacker Value
Unknown

CVE-2019-16692

Disclosure Date: September 22, 2019 (last updated November 27, 2024)
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.
Attacker Value
Unknown

CVE-2019-14826

Disclosure Date: September 17, 2019 (last updated November 27, 2024)
A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attacker could abuse this flaw if they obtain previously valid session cookies and can use this to gain access to the session.