|
211021
|
8.1 |
HIGH
Network
|
php canonical opensuse
|
php ubuntu_linux leap
|
An issue was discovered in PHP 7.x before 7.1.27 and 7.3.x before 7.3.3. phar_tar_writeheaders_int in ext/phar/tar.c has a buffer overflow via a long link value. NOTE: The vendor indicates that the l…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-9675
|
2024-11-21 13:52 |
2019-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211022
|
7.5 |
HIGH
Network
|
jtbc
|
jtbc_php
|
An issue was discovered in JTBC(PHP) 3.0.1.8. Its cache management module is flawed. An arbitrary file ending in "inc.php" can be deleted via a console/cache/manage.php?type=action&action=batch&batch…
|
CWE-22
Path Traversal
|
CVE-2019-9662
|
2024-11-21 13:52 |
2019-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211023
|
8.8 |
HIGH
Network
|
pacman_project
|
pacman
|
pacman before 5.1.3 allows directory traversal when installing a remote package via a specified URL "pacman -U <url>" due to an unsanitized file name received from a Content-Disposition header. pacma…
|
CWE-22
Path Traversal
|
CVE-2019-9686
|
2024-11-21 13:52 |
2019-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211024
|
4.8 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
Stored XSS exists in YzmCMS 5.2 via the admin/system_manage/user_config_edit.html "value" parameter,
|
CWE-79
Cross-site Scripting
|
CVE-2019-9661
|
2024-11-21 13:52 |
2019-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211025
|
4.8 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
Stored XSS exists in YzmCMS 5.2 via the admin/category/edit.html "catname" parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9660
|
2024-11-21 13:52 |
2019-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211026
|
5.3 |
MEDIUM
Network
|
checkstyle debian fedoraproject
|
checkstyle debian_linux fedora
|
Checkstyle before 8.18 loads external DTDs by default.
|
CWE-611
XXE
|
CVE-2019-9658
|
2024-11-21 13:52 |
2019-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211027
|
8.8 |
HIGH
Network
|
libofx_project debian canonical
|
libofx debian_linux ubuntu_linux
|
An issue was discovered in LibOFX 0.9.14. There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx_sgml.cpp, as demonstrated by ofxdump.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-9656
|
2024-11-21 13:52 |
2019-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211028
|
9.1 |
CRITICAL
Network
|
chuango eminent
|
wifi_alarm_system_firmware wifi\/cellular_smart_home_system_h4_plus_firmware awv_plus_wifi_alarm_system_firmware g5w_3g_firmware g5_plus_gsm\/sms\/rfid_touch_alarm_system_firmware g3_g…
|
The Chuango 433 MHz burglar-alarm product line uses static codes in the RF remote control, allowing an attacker to arm, disarm, or trigger the alarm remotely via replay attacks, as demonstrated by Ch…
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2019-9659
|
2024-11-21 13:52 |
2019-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211029
|
8.8 |
HIGH
Network
|
sdcms
|
sdcms
|
There is a CSRF in SDCMS V1.7 via an m=admin&c=theme&a=edit request. It allows PHP code injection by providing a filename in the file parameter, and providing file content in the t2 parameter.
|
CWE-352
Origin Validation Error
|
CVE-2019-9652
|
2024-11-21 13:52 |
2019-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211030
|
9.8 |
CRITICAL
Network
|
sdcms
|
sdcms
|
An issue was discovered in SDCMS V1.7. In the \app\admin\controller\themecontroller.php file, the check_bad() function's filtering is not strict, resulting in PHP code execution. This occurs because …
|
CWE-94
Code Injection
|
CVE-2019-9651
|
2024-11-21 13:52 |
2019-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|