|
223141
|
5.5 |
MEDIUM
Local
|
exiv2 fedoraproject
|
exiv2 fedora
|
A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (large heap allocation followed by a very long running loop) via a crafted WEBP imag…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-13111
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223142
|
6.5 |
MEDIUM
Network
|
exiv2 fedoraproject canonical debian
|
exiv2 fedora ubuntu_linux debian_linux
|
A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted CRW image file.
|
CWE-125 CWE-190
Out-of-bounds Read Integer Overflow or Wraparound
|
CVE-2019-13110
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223143
|
6.5 |
MEDIUM
Network
|
exiv2 fedoraproject
|
exiv2 fedora
|
An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a chunkLength - iccOffset…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-13109
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223144
|
6.5 |
MEDIUM
Network
|
exiv2 fedoraproject
|
exiv2 fedora
|
An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a zero value for iccOffse…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-13108
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223145
|
9.8 |
CRITICAL
Network
|
matio_project fedoraproject
|
matio fedora
|
Multiple integer overflows exist in MATIO before 1.5.16, related to mat.c, mat4.c, mat5.c, mat73.c, and matvar_struct.c
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-13107
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223146
|
9.8 |
CRITICAL
Network
|
cszcms
|
csz_cms
|
core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter.
|
CWE-89
SQL Injection
|
CVE-2019-13086
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223147
|
7.8 |
HIGH
Local
|
xnview
|
xnview
|
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000030ecfa.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13085
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223148
|
7.8 |
HIGH
Local
|
xnview
|
xnview
|
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000026b739.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13084
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223149
|
7.8 |
HIGH
Local
|
xnview
|
xnview
|
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000384e2a.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13083
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223150
|
9.8 |
CRITICAL
Network
|
chamilo
|
chamilo_lms
|
Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive before checking its content, and once it has been extra…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-13082
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|