|
223021
|
6.1 |
MEDIUM
Network
|
otcms
|
otcms
|
OTCMS 3.81 allows XSS via the mode parameter in an apiRun.php?mudi=autoRun request.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13971
|
2024-11-21 13:25 |
2019-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223022
|
6.1 |
MEDIUM
Network
|
antsword_project
|
antsword
|
In antSword before 2.1.0, self-XSS in the database configuration leads to code execution via modules/database/asp/index.js, modules/database/custom/index.js, modules/database/index.js, or modules/dat…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13970
|
2024-11-21 13:25 |
2019-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223023
|
8.8 |
HIGH
Network
|
metinfo
|
metinfo
|
Metinfo 6.x allows SQL Injection via the id parameter in an admin/index.php?n=ui_set&m=admin&c=index&a=doget_text_content&table=lang&field=1 request.
|
CWE-89
SQL Injection
|
CVE-2019-13969
|
2024-11-21 13:25 |
2019-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223024
|
9.8 |
CRITICAL
Network
|
videolan opensuse debian canonical
|
vlc_media_player leap backports_sle debian_linux ubuntu_linux
|
lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-13962
|
2024-11-21 13:25 |
2019-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223025
|
8.8 |
HIGH
Network
|
flatcore
|
flatcore
|
A CSRF vulnerability was found in flatCore before 1.5, leading to the upload of arbitrary .php files via acp/core/files.upload-script.php.
|
CWE-352
Origin Validation Error
|
CVE-2019-13961
|
2024-11-21 13:25 |
2019-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223026
|
5.5 |
MEDIUM
Local
|
libjpeg-turbo
|
libjpeg-turbo
|
In libjpeg-turbo 2.0.2, a large amount of memory can be used during processing of an invalid progressive JPEG image containing incorrect width and height values in the image header. NOTE: the vendor'…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-13960
|
2024-11-21 13:25 |
2019-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223027
|
6.5 |
MEDIUM
Network
|
axiosys
|
bento4
|
In Bento4 1.5.1-627, AP4_DataBuffer::SetDataSize does not handle reallocation failures, leading to a memory copy into a NULL pointer. This is different from CVE-2018-20186.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-13959
|
2024-11-21 13:25 |
2019-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223028
|
9.8 |
CRITICAL
Network
|
codersclub
|
discuz\!ml
|
Discuz!ML 3.2 through 3.4 allows remote attackers to execute arbitrary PHP code via a modified language cookie, as demonstrated by changing 4gH4_0df5_language=en to 4gH4_0df5_language=en'.phpinfo().'…
|
CWE-94
Code Injection
|
CVE-2019-13956
|
2024-11-21 13:25 |
2019-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223029
|
9.8 |
CRITICAL
Network
|
gdnsd
|
gdnsd
|
The set_ipv6() function in zscan_rfc1035.rl in gdnsd before 2.4.3 and 3.x before 3.2.1 has a stack-based buffer overflow via a long and malformed IPv6 address in zone data.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13952
|
2024-11-21 13:25 |
2019-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223030
|
9.8 |
CRITICAL
Network
|
gdnsd
|
gdnsd
|
The set_ipv4() function in zscan_rfc1035.rl in gdnsd 3.x before 3.2.1 has a stack-based buffer overflow via a long and malformed IPv4 address in zone data.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13951
|
2024-11-21 13:25 |
2019-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|