|
223981
|
7.8 |
HIGH
Local
|
autotrace_project fedoraproject
|
autotrace fedora
|
A bitmap double free in main.c in autotrace 0.31.1 allows attackers to cause an unspecified impact via a malformed bitmap image. This may occur after the use-after-free in CVE-2017-9182.
|
CWE-415
Double Free
|
CVE-2019-19005
|
2024-11-21 13:33 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223982
|
3.3 |
LOW
Local
|
autotrace_project fedoraproject
|
autotrace fedora
|
A biWidth*biBitCnt integer overflow in input-bmp.c in autotrace 0.31.1 allows attackers to provide an unexpected input value to malloc via a malformed bitmap image.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-19004
|
2024-11-21 13:33 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223983
|
9.8 |
CRITICAL
Network
|
sparkdevnetwork
|
rock_rms
|
Rock RMS versions before 8.10 and versions 9.0 through 9.3 fails to properly validate files uploaded in the application. The only protection mechanism is a file-extension blacklist that can be bypass…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-18643
|
2024-11-21 13:33 |
2021-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223984
|
9.8 |
CRITICAL
Network
|
sparkdevnetwork
|
rock_rms
|
Rock RMS version before 8.6 is vulnerable to account takeover by tampering with the user ID parameter in the profile update feature. The lack of validation and use of sequential user IDs allows any u…
|
NVD-CWE-noinfo
|
CVE-2019-18642
|
2024-11-21 13:33 |
2021-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223985
|
6.5 |
MEDIUM
Network
|
un4seen
|
bass
|
The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Denial of Service vulnerability (infinite loop) via a crafted .mp3 file. This weakness could allow attackers to consume…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-18796
|
2024-11-21 13:33 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223986
|
6.5 |
MEDIUM
Network
|
un4seen
|
bass
|
The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile out of bounds read vulnerability via a crafted .wav file. An attacker can exploit this issues to gain access to sensiti…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-18795
|
2024-11-21 13:33 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223987
|
6.5 |
MEDIUM
Network
|
un4seen
|
bass
|
The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Use after Free vulnerability via a crafted .ogg file. An attacker can exploit this to gain access to sensitive informat…
|
CWE-416
Use After Free
|
CVE-2019-18794
|
2024-11-21 13:33 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223988
|
5.4 |
MEDIUM
Adjacent
|
qualcomm
|
atheros_ar9132_firmware atheros_ar9283_firmware atheros_ar9285_firmware
|
A partial authentication bypass vulnerability exists on Atheros AR9132 3.60(AMX.8), AR9283 1.85, and AR9285 1.0.0.12NA devices. The vulnerability allows sending an unencrypted data frame to a WPA2-pr…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2019-18991
|
2024-11-21 13:33 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223989
|
5.4 |
MEDIUM
Adjacent
|
realtek
|
rtl8812ar_firmware rtl8196d_firmware rtl8192er_firmware rtl8881an_firmware
|
A partial authentication bypass vulnerability exists on Realtek RTL8812AR 1.21WW, RTL8196D 1.0.0, RTL8192ER 2.10, and RTL8881AN 1.09 devices. The vulnerability allows sending an unencrypted data fram…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2019-18990
|
2024-11-21 13:33 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223990
|
5.4 |
MEDIUM
Adjacent
|
mediatek
|
mt7620n_firmware
|
A partial authentication bypass vulnerability exists on Mediatek MT7620N 1.06 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is r…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2019-18989
|
2024-11-21 13:33 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|