|
211121
|
6.1 |
MEDIUM
Network
|
python
|
python
|
An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the fir…
|
CWE-93
CRLF Injection
|
CVE-2019-9947
|
2024-11-21 13:52 |
2019-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211122
|
9.8 |
CRITICAL
Network
|
softnas
|
cloud
|
SoftNAS Cloud 4.2.0 and 4.2.1 allows remote command execution. The NGINX default configuration file has a check to verify the status of a user cookie. If not set, a user is redirected to the login pa…
|
NVD-CWE-noinfo
|
CVE-2019-9945
|
2024-11-21 13:52 |
2019-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211123
|
3.7 |
LOW
Network
|
symfony debian
|
twig debian_linux
|
A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed b…
|
NVD-CWE-noinfo
|
CVE-2019-9942
|
2024-11-21 13:52 |
2019-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211124
|
5.3 |
MEDIUM
Network
|
coreftp
|
core_ftp
|
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the ro…
|
CWE-22
Path Traversal
|
CVE-2019-9649
|
2024-11-21 13:52 |
2019-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211125
|
5.3 |
MEDIUM
Network
|
coreftp
|
core_ftp
|
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker …
|
CWE-22
Path Traversal
|
CVE-2019-9648
|
2024-11-21 13:52 |
2019-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211126
|
8.8 |
HIGH
Adjacent
|
ushareit
|
shareit
|
The SHAREit application before 4.0.36 for Android allows a remote attacker (on the same network or joining public "open" Wi-Fi hotspots created by the application when file transfer is initiated) to …
|
NVD-CWE-noinfo
|
CVE-2019-9939
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211127
|
5.3 |
MEDIUM
Adjacent
|
ushareit
|
shareit
|
The SHAREit application before 4.0.42 for Android allows a remote attacker (on the same network or joining public "open" Wi-Fi hotspots created by the application when file transfer is initiated) to …
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-9938
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211128
|
7.5 |
HIGH
Network
|
sqlite
|
sqlite
|
In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL Pointer Dereference in fts5ChunkIterate in sqlite3.c. This is related to ext/fts…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-9937
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211129
|
7.5 |
HIGH
Network
|
sqlite
|
sqlite
|
In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlite3.c, which may lead to an information leak. This is relate…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-9936
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211130
|
9.8 |
CRITICAL
Network
|
caret
|
caret
|
Caret before 2019-02-22 allows Remote Code Execution.
|
NVD-CWE-noinfo
|
CVE-2019-9927
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|