|
213081
|
6.5 |
MEDIUM
Network
|
foxitsoftware
|
phantompdf reader
|
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-6728
|
2024-11-21 13:47 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213082
|
8.8 |
HIGH
Network
|
foxitsoftware
|
phantompdf reader
|
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must vi…
|
CWE-416
Use After Free
|
CVE-2019-6727
|
2024-11-21 13:47 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213083
|
7.5 |
HIGH
Network
|
imagemagick opensuse debian canonical
|
imagemagick leap debian_linux ubuntu_linux
|
In ImageMagick before 7.0.8-25, some memory leaks exist in DecodeImage in coders/pcd.c.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-7175
|
2024-11-21 13:47 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213084
|
5.5 |
MEDIUM
Local
|
avaya
|
one-x_communicator
|
Avaya one-X Communicator uses weak cryptographic algorithms in the client authentication component that could allow a local attacker to decrypt sensitive information. Affected versions include all 6.…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-7006
|
2024-11-21 13:47 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213085
|
9.8 |
CRITICAL
Network
|
sqlalchemy debian opensuse redhat oracle
|
sqlalchemy debian_linux leap backports_sle enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus enterprise_linux communications_operations_monitor
|
SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.
|
CWE-89
SQL Injection
|
CVE-2019-7164
|
2024-11-21 13:47 |
2019-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213086
|
8.1 |
HIGH
Network
|
linux debian canonical f5 redhat
|
linux_kernel debian_linux ubuntu_linux big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_access_policy…
|
In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free.
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2019-6974
|
2024-11-21 13:47 |
2019-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213087
|
7.5 |
HIGH
Network
|
djangoproject canonical fedoraproject
|
django ubuntu_linux fedora
|
Django 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6 allows Uncontrolled Memory Consumption via a malicious attacker-supplied value to the django.utils.numberformat.format() func…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-6975
|
2024-11-21 13:47 |
2019-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213088
|
9.8 |
CRITICAL
Network
|
css-tricks
|
chat2
|
An issue was discovered in CSS-TRICKS Chat2 through 2015-05-05. The userid parameter in jumpin.php has a SQL injection vulnerability.
|
CWE-89
SQL Injection
|
CVE-2019-7316
|
2024-11-21 13:47 |
2019-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213089
|
9.8 |
CRITICAL
Network
|
live555 debian
|
streaming_media debian_linux
|
liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up, which could lead to a Use-After-Free error that causes the RTSP server…
|
CWE-416
Use After Free
|
CVE-2019-7314
|
2024-11-21 13:47 |
2019-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213090
|
6.1 |
MEDIUM
Network
|
buildbot
|
buildbot
|
www/resource.py in Buildbot before 1.8.1 allows CRLF injection in the Location header of /auth/login and /auth/logout via the redirect parameter. This affects other web sites in the same domain.
|
CWE-93
CRLF Injection
|
CVE-2019-7313
|
2024-11-21 13:47 |
2019-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|