|
211971
|
8.8 |
HIGH
Network
|
wtcms_project
|
wtcms
|
An issue was discovered in WTCMS 1.0. It allows index.php?g=admin&m=setting&a=site_post CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-8910
|
2024-11-21 13:50 |
2019-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211972
|
7.5 |
HIGH
Network
|
wtcms_project
|
wtcms
|
An issue was discovered in WTCMS 1.0. It allows remote attackers to cause a denial of service (resource consumption) via crafted dimensions for the verification code image.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-8909
|
2024-11-21 13:50 |
2019-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211973
|
9.8 |
CRITICAL
Network
|
wtcms_project
|
wtcms
|
An issue was discovered in WTCMS 1.0. It allows remote attackers to execute arbitrary PHP code by going to the "Setting -> Mailbox configuration -> Registration email template" screen, and uploading …
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2019-8908
|
2024-11-21 13:50 |
2019-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211974
|
8.8 |
HIGH
Network
|
file_project debian opensuse canonical
|
file debian_linux leap ubuntu_linux
|
do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified other impact.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-8907
|
2024-11-21 13:50 |
2019-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211975
|
4.4 |
MEDIUM
Local
|
file_project canonical opensuse apple
|
file ubuntu_linux leap mac_os_x iphone_os watchos tvos
|
do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-8906
|
2024-11-21 13:50 |
2019-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211976
|
4.4 |
MEDIUM
Local
|
debian file_project canonical opensuse
|
debian_linux file ubuntu_linux leap
|
do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-8905
|
2024-11-21 13:50 |
2019-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211977
|
8.8 |
HIGH
Network
|
file_project canonical
|
file ubuntu_linux
|
do_bid_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printf and file_vprintf.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-8904
|
2024-11-21 13:50 |
2019-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211978
|
7.5 |
HIGH
Network
|
totaljs
|
total.js
|
index.js in Total.js Platform before 3.2.3 allows path traversal.
|
CWE-22
Path Traversal
|
CVE-2019-8903
|
2024-11-21 13:50 |
2019-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211979
|
5.7 |
MEDIUM
Network
|
idreamsoft
|
icms
|
An issue was discovered in idreamsoft iCMS through 7.0.14. A CSRF vulnerability can delete users' articles via the public/api.php?app=user URI.
|
CWE-352
Origin Validation Error
|
CVE-2019-8902
|
2024-11-21 13:50 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211980
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x
|
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, macOS Catalina 10.15. A malicious appl…
|
NVD-CWE-noinfo
|
CVE-2019-8509
|
2024-11-21 13:49 |
2020-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|