|
224721
|
6.5 |
MEDIUM
Network
|
exiv2 debian canonical
|
exiv2 debian_linux ubuntu_linux
|
Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage_int.cpp, because there is no validation of …
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-17402
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224722
|
3.3 |
LOW
Local
|
liblnk_project
|
liblnk
|
libyal liblnk 20191006 has a heap-based buffer over-read in the network_share_name_offset>20 code block of liblnk_location_information_read_data in liblnk_location_information.c, a different issue th…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-17401
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224723
|
9.8 |
CRITICAL
Network
|
joomlashack
|
shack_forms_pro
|
The Shack Forms Pro extension before 4.0.32 for Joomla! allows path traversal via a file attachment.
|
CWE-22
Path Traversal
|
CVE-2019-17399
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224724
|
7.5 |
HIGH
Network
|
riot-os
|
riot
|
In RIOT 2019.07, the MQTT-SN implementation (asymcute) mishandles errors occurring during a read operation on a UDP socket. The receive loop ends. This allows an attacker (via a large packet) to prev…
|
NVD-CWE-noinfo
|
CVE-2019-17389
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224725
|
6.1 |
MEDIUM
Network
|
eleopard
|
animate_it\!
|
The animate-it plugin before 2.3.5 for WordPress has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17385
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224726
|
6.1 |
MEDIUM
Network
|
eleopard
|
animate_it\!
|
The animate-it plugin before 2.3.4 for WordPress has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17384
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224727
|
9.8 |
CRITICAL
Network
|
netaddr_project
|
netaddr
|
The netaddr gem before 2.0.4 for Ruby has misconfigured file permissions, such that a gem install may result in 0777 permissions in the target filesystem.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-17383
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224728
|
6.1 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528).
|
CWE-79
Cross-site Scripting
|
CVE-2019-17380
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224729
|
6.1 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 82.0.15 allows self stored XSS in the WHM SSL Storage Manager interface (SEC-527).
|
CWE-79
Cross-site Scripting
|
CVE-2019-17379
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224730
|
6.1 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 82.0.15 allows self XSS in the SSL Key Delete interface (SEC-526).
|
CWE-79
Cross-site Scripting
|
CVE-2019-17378
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|