|
211351
|
9.8 |
CRITICAL
Network
|
gracemedia_media_player_project
|
gracemedia_media_player
|
The GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the "cfg" parameter.
|
CWE-22
Path Traversal
|
CVE-2019-9618
|
2024-11-21 13:51 |
2019-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211352
|
9.8 |
CRITICAL
Network
|
printerlogic
|
print_management
|
The PrinterLogic Print Management software, versions up to and including 18.3.1.96, does not sanitize special characters allowing for remote unauthorized changes to configuration files. An unauthenti…
|
NVD-CWE-Other
|
CVE-2019-9505
|
2024-11-21 13:51 |
2019-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211353
|
8.8 |
HIGH
Network
|
strato telekom ionos
|
hidrive_desktop_client magentacloud 1\&1_online_storage
|
STRATO HiDrive Desktop Client 5.0.1.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the HiDriveMaintenanceService service. This service establishes a NetNamedPipe endpo…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2019-9486
|
2024-11-21 13:51 |
2019-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211354
|
7.5 |
HIGH
Network
|
zimbra
|
collaboration_server
|
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-9621
|
2024-11-21 13:51 |
2019-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211355
|
7.8 |
HIGH
Local
|
datools
|
daviewindy
|
DaviewIndy 8.98.7 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed PDF file that is mishandled by Daview.exe. Attackers could exploit this and arb…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-9139
|
2024-11-21 13:51 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211356
|
7.8 |
HIGH
Local
|
datools
|
daviewindy
|
DaviewIndy 8.98.7 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed PhotoShop file that is mishandled by Daview.exe. Attackers could exploit this a…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-9138
|
2024-11-21 13:51 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211357
|
7.8 |
HIGH
Local
|
hmtalk
|
daviewindy
|
DaviewIndy 8.98.7 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed Image file that is mishandled by Daview.exe. Attackers could exploit this and a…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-9137
|
2024-11-21 13:51 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211358
|
7.8 |
HIGH
Local
|
datools
|
daviewindy
|
DaviewIndy 8.98.7 and earlier versions have a Heap-based overflow vulnerability, triggered when the user opens a malformed JPEG2000 format file that is mishandled by Daview.exe. Attackers could explo…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9136
|
2024-11-21 13:51 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211359
|
7.8 |
HIGH
Local
|
datools
|
daviewindy
|
DaviewIndy 8.98.7 and earlier versions have a Heap-based overflow vulnerability, triggered when the user opens a malformed DIB format file that is mishandled by Daview.exe. Attackers could exploit th…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9135
|
2024-11-21 13:51 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211360
|
9.8 |
CRITICAL
Network
|
xinruidz
|
sundray_wan_controller_firmware
|
WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and earlier has a Remote Code Execution issue allowing remote attackers to achieve full access to the system, because shell metacharacters i…
|
CWE-78
OS Command
|
CVE-2019-9161
|
2024-11-21 13:51 |
2019-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|