|
221851
|
7.8 |
HIGH
Local
|
gonitro
|
nitropdf
|
A specifically crafted jpeg2000 file embedded in a PDF file can lead to a heap corruption when opening a PDF document in NitroPDF 12.12.1.522. With careful memory manipulation, this can lead to arbit…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-5045
|
2024-11-21 13:44 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221852
|
8.8 |
HIGH
Network
|
foxitsoftware
|
phantompdf reader
|
An exploitable memory corruption vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, version 9.4.1.16828. A specially crafted PDF document can trigger an out-of-memory…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-5031
|
2024-11-21 13:44 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221853
|
6.7 |
MEDIUM
Local
|
e2fsprogs_project debian fedoraproject canonical netapp
|
e2fsprogs debian_linux fedora ubuntu_linux solidfire hci_management_node
|
An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap, resulting in c…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-5094
|
2024-11-21 13:44 |
2019-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221854
|
9.8 |
CRITICAL
Network
|
aspose
|
aspose.pdf_for_c\+\+
|
An uninitialized memory access vulnerability exists in the way Aspose.PDF 19.2 for C++ handles invalid parent object pointers. A specially crafted PDF can cause a read and write from uninitialized me…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2019-5067
|
2024-11-21 13:44 |
2019-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221855
|
9.8 |
CRITICAL
Network
|
aspose
|
aspose.pdf_for_c\+\+
|
An exploitable use-after-free vulnerability exists in the way LZW-compressed streams are processed in Aspose.PDF 19.2 for C++. A specially crafted PDF can cause a dangling heap pointer, resulting in …
|
CWE-416
Use After Free
|
CVE-2019-5066
|
2024-11-21 13:44 |
2019-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221856
|
8.8 |
HIGH
Network
|
aspose
|
aspose.pdf_for_c\+\+
|
An exploitable Use-After-Free vulnerability exists in the way FunctionType 0 PDF elements are processed in Aspose.PDF 19.2 for C++. A specially crafted PDF can cause a dangling heap pointer, resultin…
|
CWE-416
Use After Free
|
CVE-2019-5042
|
2024-11-21 13:44 |
2019-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221857
|
7.2 |
HIGH
Network
|
arubanetworks
|
arubaos
|
A command injection vulnerability is present in the web management interface of ArubaOS that permits an authenticated user to execute arbitrary commands on the underlying operating system. A maliciou…
|
CWE-78
OS Command
|
CVE-2019-5315
|
2024-11-21 13:44 |
2019-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221858
|
6.1 |
MEDIUM
Network
|
arubanetworks
|
arubaos
|
Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS. An attacker would be able to accomplish this by sending certain URL parameter…
|
CWE-74
Injection
|
CVE-2019-5314
|
2024-11-21 13:44 |
2019-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221859
|
7.5 |
HIGH
Network
|
netgear
|
wnr2000_firmware
|
An exploitable denial-of-service vulnerability exists in the Host Access Point Daemon (hostapd) on the NETGEAR N300 (WNR2000v5 with Firmware Version V1.0.0.70) wireless router. A SOAP request sent in…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-5055
|
2024-11-21 13:44 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221860
|
7.5 |
HIGH
Network
|
netgear
|
wnr2000_firmware
|
An exploitable denial-of-service vulnerability exists in the session handling functionality of the NETGEAR N300 (WNR2000v5 with Firmware Version V1.0.0.70) HTTP server. An HTTP request with an empty …
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-5054
|
2024-11-21 13:44 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|