|
224921
|
6.5 |
MEDIUM
Network
|
xen debian fedoraproject
|
xen debian_linux fedora
|
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via a VCPUOP_initialise hypercall. hypercall_create_continuation() is a variadic function whi…
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2019-18420
|
2024-11-21 13:33 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224922
|
5.9 |
MEDIUM
Network
|
totaldefense
|
anti-virus
|
The malware scan function in Total Defense Anti-virus 11.5.2.28 is vulnerable to a TOCTOU bug; consequently, symbolic link attacks allow privileged files to be deleted.
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2019-18644
|
2024-11-21 13:33 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224923
|
7.5 |
HIGH
Network
|
themooltipass
|
moolticute
|
An issue was discovered in Mooltipass Moolticute through v0.42.1 and v0.42.x-testing through v0.42.5-testing. There is a NULL pointer dereference in MPDevice_win.cpp.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-18635
|
2024-11-21 13:33 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224924
|
9.8 |
CRITICAL
Network
|
europa
|
eidas-node_integration_package
|
European Commission eIDAS-Node Integration Package before 2.3.1 has Missing Certificate Validation because a certain ExplicitKeyTrustEvaluator return value is not checked. NOTE: only 2.1 is confirmed…
|
CWE-295
Improper Certificate Validation
|
CVE-2019-18633
|
2024-11-21 13:33 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224925
|
9.8 |
CRITICAL
Network
|
europa
|
eidas-node_integration_package
|
European Commission eIDAS-Node Integration Package before 2.3.1 allows Certificate Faking because an attacker can sign a manipulated SAML response with a forged certificate.
|
CWE-295
Improper Certificate Validation
|
CVE-2019-18632
|
2024-11-21 13:33 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224926
|
9.8 |
CRITICAL
Network
|
opera
|
mini
|
Opera Mini for Android allows attackers to bypass intended restrictions on .apk file download/installation via an RTLO (aka Right to Left Override) approach, as demonstrated by misinterpretation of m…
|
NVD-CWE-noinfo
|
CVE-2019-18624
|
2024-11-21 13:33 |
2019-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224927
|
5.3 |
MEDIUM
Network
|
mediawiki
|
abusefilter
|
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Previously hidden (restricted) AbuseFilter filters were viewable (or their differences were viewable) to unprivileged …
|
CWE-200
Information Exposure
|
CVE-2019-18612
|
2024-11-21 13:33 |
2019-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224928
|
6.5 |
MEDIUM
Network
|
mediawiki
|
checkuser
|
An issue was discovered in the CheckUser extension through 1.34 for MediaWiki. Certain sensitive information within oversighted edit summaries made available via the MediaWiki API was potentially vis…
|
CWE-200
Information Exposure
|
CVE-2019-18611
|
2024-11-21 13:33 |
2019-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224929
|
7.5 |
HIGH
Network
|
cezerin
|
cezerin
|
Cezerin v0.33.0 allows unauthorized order-information modification because certain internal attributes can be overwritten via a conflicting name when processing order requests. Hence, a malicious cus…
|
NVD-CWE-noinfo
|
CVE-2019-18608
|
2024-11-21 13:33 |
2019-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224930
|
9.8 |
CRITICAL
Network
|
axohelp.c_project axodraw2_project
|
axohelp.c axodraw2
|
In axohelp.c before 1.3 in axohelp in axodraw2 before 2.1.1b, as distributed in TeXLive and other collections, sprintf is mishandled.
|
NVD-CWE-noinfo
|
CVE-2019-18604
|
2024-11-21 13:33 |
2019-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|