|
223451
|
7.0 |
HIGH
Local
|
canonical linux fedoraproject debian opensuse redhat
|
ubuntu_linux linux_kernel fedora debian_linux leap enterprise_linux enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus
|
arch/powerpc/mm/mmu_context_book3s64.c in the Linux kernel before 5.1.15 for powerpc has a bug where unrelated processes may be able to read/write to one another's virtual memory under certain condit…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-12817
|
2024-11-21 13:23 |
2019-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223452
|
6.1 |
MEDIUM
Network
|
netgate
|
pfsense
|
In pfSense 2.4.4-p2 and 2.4.4-p3, if it is possible to trick an authenticated administrator into clicking on a button on a phishing page, an attacker can leverage XSS to upload arbitrary executable c…
|
CWE-79
Cross-site Scripting
|
CVE-2019-12949
|
2024-11-21 13:23 |
2019-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223453
|
5.5 |
MEDIUM
Local
|
glyphandcog
|
xpdfreader
|
In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in FoFiType1C::convertToType0 in fofi/FoFiType1C.cc when it is trying to access the second privateDicts array element, because the pr…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-12958
|
2024-11-21 13:23 |
2019-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223454
|
7.8 |
HIGH
Local
|
glyphandcog fedoraproject
|
xpdfreader fedora
|
In Xpdf 4.01.01, a buffer over-read could be triggered in FoFiType1C::convertToType1 in fofi/FoFiType1C.cc when the index number is larger than the charset array bounds. It can, for example, be trigg…
|
CWE-125 CWE-129
Out-of-bounds Read Improper Validation of Array Index
|
CVE-2019-12957
|
2024-11-21 13:23 |
2019-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223455
|
9.8 |
CRITICAL
Network
|
cesanta
|
mongoose
|
An issue was discovered in Mongoose before 6.15. The parse_mqtt() function in mg_mqtt.c has a critical heap-based buffer overflow.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-12951
|
2024-11-21 13:23 |
2019-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223456
|
4.3 |
MEDIUM
Network
|
bcnquark
|
quarking_password_manager
|
BCN Quark Quarking Password Manager 3.1.84 suffers from a clickjacking vulnerability caused by allowing * within web_accessible_resources. An attacker can take advantage of this vulnerability and cau…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2019-12880
|
2024-11-21 13:23 |
2019-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223457
|
5.9 |
MEDIUM
Network
|
livezilla
|
livezilla
|
LiveZilla Server before 8.0.1.1 is vulnerable to Denial Of Service (memory consumption) in knowledgebase.php via a large integer value of the depth parameter.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-12940
|
2024-11-21 13:23 |
2019-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223458
|
9.8 |
CRITICAL
Network
|
livezilla
|
livezilla
|
LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in server.php via the p_ext_rse parameter.
|
CWE-89
SQL Injection
|
CVE-2019-12939
|
2024-11-21 13:23 |
2019-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223459
|
8.8 |
HIGH
Network
|
phoenixcontact
|
automationworx_software_suite
|
An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Uninitialized P…
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2019-12870
|
2024-11-21 13:23 |
2019-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223460
|
8.8 |
HIGH
Network
|
phoenixcontact
|
automationworx_software_suite
|
An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Out-Of-Bounds R…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-12869
|
2024-11-21 13:23 |
2019-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|