|
223491
|
6.5 |
MEDIUM
Network
|
alpinelinux
|
abuild
|
Alpine Linux abuild through 3.4.0 allows an unprivileged member of the abuild group to add an untrusted package via a --keys-dir option that causes acceptance of an untrusted signing key.
|
CWE-668 CWE-862
Exposure of Resource to Wrong Sphere Missing Authorization
|
CVE-2019-12875
|
2024-11-21 13:23 |
2019-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223492
|
9.8 |
CRITICAL
Network
|
videolan
|
vlc_media_player
|
An issue was discovered in zlib_decompress_extra in modules/demux/mkv/util.cpp in VideoLAN VLC media player 3.x through 3.0.7. The Matroska demuxer, while parsing a malformed MKV file type, has a dou…
|
CWE-415
Double Free
|
CVE-2019-12874
|
2024-11-21 13:23 |
2019-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223493
|
7.2 |
HIGH
Network
|
dotcms
|
dotcms
|
dotCMS before 5.1.6 is vulnerable to a SQL injection that can be exploited by an attacker of the role Publisher via view_unpushed_bundles.jsp.
|
CWE-89
SQL Injection
|
CVE-2019-12872
|
2024-11-21 13:23 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223494
|
6.1 |
MEDIUM
Network
|
craftcms
|
craft_cms
|
Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12823
|
2024-11-21 13:23 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223495
|
7.2 |
HIGH
Network
|
misp
|
misp
|
app/Model/Server.php in MISP 2.4.109 allows remote command execution by a super administrator because the PHP file_exists function is used with user-controlled entries, and phar:// URLs trigger deser…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-12868
|
2024-11-21 13:23 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223496
|
5.5 |
MEDIUM
Local
|
radare
|
radare2
|
In radare2 through 3.5.1, cmd_mount in libr/core/cmd_mount.c has a double free for the ms command.
|
CWE-415
Double Free
|
CVE-2019-12865
|
2024-11-21 13:23 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223497
|
6.1 |
MEDIUM
Network
|
seeddms
|
seeddms
|
out/out.GroupMgr.php in SeedDMS 5.1.11 has Stored XSS by making a new group with a JavaScript payload as the "GROUP" Name.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12801
|
2024-11-21 13:23 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223498
|
9.8 |
CRITICAL
Network
|
wago
|
852-303_firmware 852-1305_firmware 852-1505_firmware
|
WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded users and passwords that can be used to login via SSH and TELNET.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-12550
|
2024-11-21 13:23 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223499
|
9.8 |
CRITICAL
Network
|
wago
|
852-303_firmware 852-1305_firmware 852-1505_firmware
|
WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded private keys for the SSH daemon. The fingerprint of the SSH host key from the corresponding SSH daem…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-12549
|
2024-11-21 13:23 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223500
|
6.8 |
MEDIUM
Physics
|
actiontec
|
t2200h_firmware
|
An issue was discovered on Actiontec T2200H T2200H-31.128L.08 devices, as distributed by Telus. By attaching a UART adapter to the UART pins on the system board, an attacker can use a special key seq…
|
NVD-CWE-noinfo
|
CVE-2019-12789
|
2024-11-21 13:23 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|