|
222631
|
7.8 |
HIGH
Local
|
videolan debian
|
vlc_media_player debian_linux
|
The xiph_SplitHeaders function in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 does not check array bounds properly. As a result, a heap-based buffer over-read can be triggered via a cra…
|
CWE-125 CWE-129
Out-of-bounds Read Improper Validation of Array Index
|
CVE-2019-14437
|
2024-11-21 13:26 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222632
|
9.8 |
CRITICAL
Network
|
imagely
|
nextgen_gallery
|
A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrar…
|
CWE-89
SQL Injection
|
CVE-2019-14314
|
2024-11-21 13:26 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222633
|
9.8 |
CRITICAL
Network
|
ricoh
|
sp_c250sf_firmware sp_c252sf_firmware sp_c250dn_firmware sp_c252dn_firmware
|
Several Ricoh printers have multiple buffer overflows parsing HTTP parameter settings for SNMP, which allow an attacker to cause a denial of service or code execution via crafted requests to the web …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-14307
|
2024-11-21 13:26 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222634
|
9.8 |
CRITICAL
Network
|
ricoh
|
sp_c250sf_firmware sp_c252sf_firmware sp_c250dn_firmware sp_c252dn_firmware
|
Several Ricoh printers have multiple buffer overflows parsing HTTP parameter settings for Wi-Fi, mDNS, POP3, SMTP, and notification alerts, which allow an attacker to cause a denial of service or cod…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-14305
|
2024-11-21 13:26 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222635
|
9.8 |
CRITICAL
Network
|
ricoh
|
sp_c250sf_firmware sp_c252sf_firmware sp_c250dn_firmware sp_c252dn_firmware
|
Several Ricoh printers have multiple buffer overflows parsing HTTP cookie headers, which allow an attacker to cause a denial of service or code execution via crafted requests to the web server. Affec…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-14300
|
2024-11-21 13:26 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222636
|
9.8 |
CRITICAL
Network
|
ricoh
|
sp_c250sf_firmware sp_c252sf_firmware sp_c250dn_firmware sp_c252dn_firmware
|
Several Ricoh printers have multiple buffer overflows parsing LPD packets, which allow an attacker to cause a denial of service or code execution via crafted requests to the LPD service. Affected fir…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-14308
|
2024-11-21 13:26 |
2019-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222637
|
5.4 |
MEDIUM
Network
|
sonatype
|
nexus_repository_manager
|
In Nexus Repository Manager before 3.18.0, users with elevated privileges can create stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14469
|
2024-11-21 13:26 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222638
|
7.5 |
HIGH
Network
|
sphinxsearch
|
sphinx
|
Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a firewall or reconfigured to listen to 127.0.0.1 only).
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-14511
|
2024-11-21 13:26 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222639
|
7.5 |
HIGH
Network
|
zenoss
|
zenoss
|
The XML-RPC subsystem in Zenoss 2.5.3 allows XXE attacks that lead to unauthenticated information disclosure via port 9988.
|
CWE-611
XXE
|
CVE-2019-14258
|
2024-11-21 13:26 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222640
|
7.8 |
HIGH
Local
|
zenoss
|
zenoss
|
pyraw in Zenoss 2.5.3 allows local privilege escalation by modifying environment variables to redirect execution before privileges are dropped, aka ZEN-31765.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2019-14257
|
2024-11-21 13:26 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|