|
213301
|
7.5 |
HIGH
Network
|
duraspace
|
vitro
|
SPARQL Injection in VIVO Vitro v1.10.0 allows a remote attacker to execute arbitrary SPARQL via the uri parameter, leading to a regular expression denial of service (ReDoS), as demonstrated by crafte…
|
CWE-77 CWE-400
Command Injection Uncontrolled Resource Consumption
|
CVE-2019-6986
|
2024-11-21 13:47 |
2019-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213302
|
8.8 |
HIGH
Network
|
foxitsoftware
|
3d
|
An issue was discovered in Foxit 3D Plugin Beta before 9.4.0.16807 for Foxit Reader and PhantomPDF. The application could encounter an Out-of-Bounds Read in Indexing or a Heap Overflow and crash duri…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-6985
|
2024-11-21 13:47 |
2019-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213303
|
6.5 |
MEDIUM
Network
|
foxitsoftware
|
3d
|
An issue was discovered in Foxit 3D Plugin Beta before 9.4.0.16807 for Foxit Reader and PhantomPDF. The application could encounter a Use-After-Free or Type Confusion and crash during handling of cer…
|
CWE-416 CWE-843
Use After Free Type Confusion
|
CVE-2019-6984
|
2024-11-21 13:47 |
2019-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213304
|
6.5 |
MEDIUM
Network
|
foxitsoftware
|
3d
|
An issue was discovered in Foxit 3D Plugin Beta before 9.4.0.16807 for Foxit Reader and PhantomPDF. The application could encounter an Integer Overflow and crash during the handling of certain PDF fi…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-6983
|
2024-11-21 13:47 |
2019-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213305
|
5.5 |
MEDIUM
Local
|
foxitsoftware
|
3d
|
An issue was discovered in Foxit 3D Plugin Beta before 9.4.0.16807 for Foxit Reader and PhantomPDF. The application could encounter an Out-of-Bounds Write and crash during the handling of certain PDF…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-6982
|
2024-11-21 13:47 |
2019-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213306
|
6.1 |
MEDIUM
Network
|
ip_history_logs_project
|
ip_history_logs
|
An issue was discovered in the User IP History Logs (aka IP_History_Logs) plugin 1.0.2 for MyBB. There is XSS via the admin/modules/tools/ip_history_logs.php useragent field.
|
CWE-79
Cross-site Scripting
|
CVE-2019-6979
|
2024-11-21 13:47 |
2019-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213307
|
9.8 |
CRITICAL
Network
|
libgd debian canonical
|
libgd debian_linux ubuntu_linux
|
The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. NOTE: PHP is unaffected.
|
CWE-415
Double Free
|
CVE-2019-6978
|
2024-11-21 13:47 |
2019-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213308
|
8.8 |
HIGH
Network
|
libgd php debian canonical netapp
|
libgd php debian_linux ubuntu_linux storage_automation_store
|
gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x bef…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-6977
|
2024-11-21 13:47 |
2019-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213309
|
5.3 |
MEDIUM
Network
|
libvips
|
libvips
|
libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c does not zero out allocated memory. This can resul…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2019-6976
|
2024-11-21 13:47 |
2019-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213310
|
5.9 |
MEDIUM
Network
|
phpmyadmin debian
|
phpmyadmin debian_linux
|
An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the serv…
|
NVD-CWE-noinfo
|
CVE-2019-6799
|
2024-11-21 13:47 |
2019-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|