|
211461
|
8.8 |
HIGH
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 1.5.1-628. An out of bounds write occurs in AP4_CttsTableEntry::AP4_CttsTableEntry() located in Core/Ap4Array.h. It can be triggered by sending a crafted file to (fo…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9544
|
2024-11-21 13:51 |
2019-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211462
|
8.8 |
HIGH
Network
|
freedesktop
|
poppler
|
An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) th…
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-9543
|
2024-11-21 13:51 |
2019-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211463
|
7.5 |
HIGH
Network
|
carel
|
pcoweb_card_firmware
|
The Glen Dimplex Deutschland GmbH implementation of the Carel pCOWeb configuration tool allows remote attackers to obtain access via an HTTP session on port 10000, as demonstrated by reading the mode…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-9484
|
2024-11-21 13:51 |
2019-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211464
|
9.1 |
CRITICAL
Network
|
amazon
|
ring_video_doorbell_firmware
|
Amazon Ring Doorbell before 3.4.7 mishandles encryption, which allows attackers to obtain audio and video data, or insert spoofed video that does not correspond to the actual person at the door.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-9483
|
2024-11-21 13:51 |
2019-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211465
|
5.3 |
MEDIUM
Network
|
misp
|
misp
|
In MISP 2.4.102, an authenticated user can view sightings that they should not be eligible for. Exploiting this requires access to the event that has received the sighting. The issue affects instance…
|
CWE-862
Missing Authorization
|
CVE-2019-9482
|
2024-11-21 13:51 |
2019-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211466
|
9.8 |
CRITICAL
Network
|
baigo
|
baigo_cms
|
An issue was discovered in baigo CMS 2.1.1. There is a vulnerability that allows remote attackers to execute arbitrary code. A BG_SITE_NAME parameter with malicious code can be written into the opt_b…
|
CWE-94
Code Injection
|
CVE-2019-9227
|
2024-11-21 13:51 |
2019-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211467
|
6.1 |
MEDIUM
Network
|
baigo
|
baigo_cms
|
An issue was discovered in baigo CMS 2.1.1. There is a persistent XSS vulnerability that allows remote attackers to inject arbitrary web script or HTML via the opt[base][BG_SITE_NAME] parameter to th…
|
CWE-79
Cross-site Scripting
|
CVE-2019-9226
|
2024-11-21 13:51 |
2019-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211468
|
9.8 |
CRITICAL
Network
|
live555 opensuse debian
|
streaming_media leap backports_sle debian_linux
|
In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function.
|
NVD-CWE-noinfo
|
CVE-2019-9215
|
2024-11-21 13:51 |
2019-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211469
|
7.5 |
HIGH
Network
|
wireshark debian
|
wireshark debian_linux
|
In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the RPCAP dissector could crash. This was addressed in epan/dissectors/packet-rpcap.c by avoiding an attempted dereference of a NULL conversation.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-9214
|
2024-11-21 13:51 |
2019-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211470
|
5.5 |
MEDIUM
Local
|
wireshark debian canonical opensuse
|
wireshark debian_linux ubuntu_linux leap
|
In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with e…
|
CWE-787 CWE-193
Out-of-bounds Write Off-by-one Error
|
CVE-2019-9209
|
2024-11-21 13:51 |
2019-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|