|
213261
|
7.8 |
HIGH
Local
|
freedesktop canonical debian fedoraproject redhat
|
poppler ubuntu_linux debian_linux fedora enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux enterprise_linux_eus enterprise_linu…
|
In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of service (application crash…
|
CWE-125 CWE-681
Out-of-bounds Read Incorrect Conversion between Numeric Types
|
CVE-2019-7310
|
2024-11-21 13:47 |
2019-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213262
|
5.5 |
MEDIUM
Local
|
gnu
|
glibc
|
In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the RDX most significan…
|
NVD-CWE-noinfo
|
CVE-2019-7309
|
2024-11-21 13:47 |
2019-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213263
|
5.6 |
MEDIUM
Local
|
linux canonical opensuse
|
linux_kernel ubuntu_linux leap
|
kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithmetic in various cases, including cases of different branches with different sta…
|
CWE-189
Numeric Errors
|
CVE-2019-7308
|
2024-11-21 13:47 |
2019-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213264
|
7.2 |
HIGH
Network
|
zevenet
|
zen_load_balancer
|
Zen Load Balancer 3.10.1 allows remote authenticated admin users to execute arbitrary commands as root via shell metacharacters in the index.cgi?action=View_Cert certname parameter.
|
CWE-78
OS Command
|
CVE-2019-7301
|
2024-11-21 13:47 |
2019-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213265
|
7.2 |
HIGH
Network
|
articatech
|
artica_proxy
|
Artica Proxy 3.06.200056 allows remote attackers to execute arbitrary commands as root by reading the ressources/settings.inc ldap_admin and ldap_password fields, using these credentials at logon.php…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-7300
|
2024-11-21 13:47 |
2019-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213266
|
8.1 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 request. Thi…
|
CWE-78
OS Command
|
CVE-2019-7298
|
2024-11-21 13:47 |
2019-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213267
|
9.8 |
CRITICAL
Network
|
d-link
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injection vulnerability allows attackers to execute arbitrary OS commands via shell metacharacters in a cra…
|
CWE-78
OS Command
|
CVE-2019-7297
|
2024-11-21 13:47 |
2019-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213268
|
6.1 |
MEDIUM
Network
|
typora
|
typora
|
typora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formula.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7296
|
2024-11-21 13:47 |
2019-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213269
|
6.1 |
MEDIUM
Network
|
typora
|
typora
|
typora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7295
|
2024-11-21 13:47 |
2019-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213270
|
7.4 |
HIGH
Network
|
netkit debian
|
netkit debian_linux
|
An issue was discovered in rcp in NetKit through 0.17. For an rcp operation, the server chooses which files/directories are sent to the client. However, the rcp client only performs cursory validatio…
|
NVD-CWE-noinfo
|
CVE-2019-7283
|
2024-11-21 13:47 |
2019-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|